CCE Phase 1: Consequence Prioritization
Sarah G. Freeman, USDOE Office of Cybersecurity, Energy Security, and Emergency Response (CESER), Curtis St. Michel, Nathan Johnson · 2020
Idaho National Laboratory (INL) developed the Consequence-driven Cyber-informed Engineering (CCE) methodology to provide public and private organizations with steps to work collaboratively and establish a working relationship to protect critical infrastructure and other national assets. This process is a considerable undertaking, iterative in nature, and—as time and resources allow—should become a part of a company’s culture. By focusing on the impact of potentially negative Events, CCE provides a better understanding of how and why adversaries can affect critical functions and services using cyber-enabled sabotage. This document describes Phase 1 of the CCE process.