Security Economics and Critical National Infrastructure

被引:15
|
作者
Anderson, Ross [1 ]
Fuloria, Shailendra [1 ]
机构
[1] Univ Cambridge, Comp Lab, Cambridge CB2 3QG, England
关键词
D O I
10.1007/978-1-4419-6967-5_4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
There has been considerable effort and expenditure since 9/11 on the protection of 'Critical National Infrastructure' against online attack. This is commonly interpreted to mean preventing online sabotage against utilities such as electricity, oil and gas, water, and sewage including pipelines, refineries, generators, storage depots and transport facilities such as tankers and terminals. A consensus is emerging that the protection of such assets is more a matter of business models and regulation in short, of security economics than of technology. We describe the problems, and the state of play, in this paper. Industrial control systems operate in a different world from systems previously studied by security economists; we find the same issues (lock-in, externalities, asymmetric information and so on) but in different forms. Lock-in is physical, rather than based on network effects, while the most serious externalities result from correlated failure, whether from cascade failures, common-mode failures or simultaneous attacks. There is also an interesting natural experiment happening, in that the USA is regulating cyber security in the electric power industry, but not in oil and gas, while the UK is not regulating at all but rather encouraging industry's own efforts. Some European governments are intervening, while others are leaving cybersecurity entirely to plant owners to worry about. We already note some perverse effects of the U.S. regulation regime as companies game the system, to the detriment of overall dependability.
引用
收藏
页码:55 / 66
页数:12
相关论文
共 50 条
  • [1] A critical space infrastructure perspective on Romanian national security
    Bucovetchi, Olga
    Georgescu, Alexandru
    Lazar, Marilena
    Cirnu, Carmen
    [J]. ROMANIAN JOURNAL OF INFORMATION TECHNOLOGY AND AUTOMATIC CONTROL-REVISTA ROMANA DE INFORMATICA SI AUTOMATICA, 2018, 28 (03): : 31 - 40
  • [2] Protection of Critical Infrastructure in National Cyber Security Strategies
    Izycki, Eduardo
    Colli, Rodrigo
    [J]. PROCEEDINGS OF THE 18TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2019), 2019, : 219 - 228
  • [3] UK cyber security and critical national infrastructure protection
    Stoddart, Kristan
    [J]. INTERNATIONAL AFFAIRS, 2016, 92 (05) : 1079 - 1105
  • [4] Protection of Critical Infrastructure Facilities as a Component of the National Security
    Denysov, Andrii Ighorovych
    Bershov, Hennadii Yevhenovych
    Krykun, Viacheslav Vitaliiovych
    Zhydovtseva, Olha
    [J]. CUESTIONES POLITICAS, 2021, 39 (71): : 789 - 799
  • [5] Ethics and Privacy in National Security and Critical Infrastructure Protection
    Betts, Jennifer
    Sezer, Sakir
    [J]. 2014 IEEE INTERNATIONAL SYMPOSIUM ON ETHICS IN SCIENCE, TECHNOLOGY AND ENGINEERING, 2014,
  • [6] True economics of a security infrastructure
    Oldham, A
    [J]. ISSE 2004 - SECURING ELECTRONIC BUSINESS PROCESSES, 2004, : 3 - 11
  • [8] National Security as a Corporate Social Responsibility: Critical Infrastructure Resilience
    Gail Ridley
    [J]. Journal of Business Ethics, 2011, 103 : 111 - 125
  • [9] Agricultural Security: Critical National Infrastructure We Cannot Ignore
    McCreight, Robert
    [J]. JOURNAL OF HOMELAND SECURITY AND EMERGENCY MANAGEMENT, 2022, 19 (01) : 127 - 135
  • [10] Critical Infrastructure Security
    Greenberg, Michael
    [J]. RISK ANALYSIS, 2012, 32 (08) : 1441 - 1442