Critical Information Infrastructure Protection (CIIP):Draft technical Report for the Australian Institute of Criminology
Alan N. Chantler, Roderic G. Broadhurst · QUT ePrints (Queensland University of Technology) · 2006
This chapter aims to examine vulnerability in Australia’s critical infrastructure assets and examine to what extent cyber-criminals or cyber-terrorists are able to manipulate or exploit weaknesses in the protection of these crucial services. Critical infrastructure is defined, followed by a consideration of the threats to the critical information infrastructure. The focus is on information communication technology (ICT) and the effectiveness of existing and potential countermeasures. Comprehensive Critical Information Infrastructure Protection (CIIP) planning processes have now been produced by many countries and best practices have emerged. The Crisis and Risk Network (CRN) CIIP Handbook and the situation reports of MELANI (the Swiss Agency ‘Reporting and Analysis Centre for Information Assurance) are good examples of the work being done. Significant problems remain in the evaluation and assessment of the integrity of these approaches in practice. Greater attention to potential weaknesses in SCADA (supervisory control and data acquisition) systems and rigorous penetration testing is required to ensure resilience in key critical infrastructure. Coupled with high costs to private businesses a lack of follow-through, poor continuity and co-ordination plus shallow or incomplete adoption of countermeasures have been cited as major problems in developing a resilient CIIP capacity.