Protecting cyber critical infrastructure (CCI): integrating information security risk analysis and environmental vulnerability analysis

Tom Feglar, Jackson Levy · 2005

Improving the security of "cyberspace" for critical infrastructure systems is important not only because the global economy is increasingly reliant on computer communications, but also because critical physical infrastructure, such as power distribution, water supply, national defense, and emergency services, is managed over increasingly interconnected electronic networks. These newly identified cyber critical infrastructures (CCI) require innovative risk management systems. We propose the integration of information systems risk management and environmental risk management to minimize the threats to critical infrastructure. Our information security risk analysis concept is based on ISO/IEC 17799 that is harmonized with environmental management standard ISO 14000 using model referred as Plan-Do-Check-Act (PDCA).

Read the paper · More papers on PaperTik