Improving the cyber incident mission impact assessment (CIMIA) process

Michael R. Grimaila, Robert F. Mills, Larry W. Fortson · 2008

Despite our best efforts to secure our cyberspace; we inevitably experience incidents in the cyber domain which result in the loss of the confidentiality, integrity, or availability of a cyber resource. When a cyber incident occurs, we must quickly and accurately estimate and report the resulting negative impact, not only in terms of the infrastructure damage, but also in terms of the mission impact experienced by all of the affected organizations. Unfortunately, existing methods for mission impact assessment are hindered by the lack of standardization in the way that we identify, value, track, document, and report critical cyber resources. In this presentation, we discuss the importance of accurate and timely damage assessment in military operations; distinguish between damage and mission impact assessment; motivate the need for a change in mission impact assessment; and propose that a paradigm shift is required in the way that view critical cyber resources. The proposed changes are necessary to provide commanders with dominate cyberspace battlespace knowledge and enable accurate predictive situational awareness.

Read the paper · More papers on PaperTik