In essence the executive order puts the emphasis on establishing a framework for risk management and relies on voluntary participation of the private sector that owns and operates the majority of critical infrastructure

Bound to Fail:Why Cyber Security Risk Cannot Simply Be “Managed” Away\r\f \n\t\f \b\t\f\n\f  CENTURY SECURITY AND INTELLIGENCE   \f \n\t\b Bound to Fail:Why Cyber Security Risk Cannot Simply Be “Managed” Away\r\f \n\t\f \b\t\f\n\f \f  ­\f\f\n\f\n€€€€‚\fƒ \f„\f\f\r€€‚\f\n\f\n „\fƒ…\f €\r \f†\t \f€\n\fƒ‡\fˆ\f‰\f €‚\f \n\f Š € ‚€\r  €€ €Š    \f \bƒ\f \f  €\b€ \f €\fŠ  €\f\nŠ€ \f‹\f\f \f†\f\f‰\f €‚\f \n\f \f\f€\fƒ€€\rŠ \fˆ „Š  €„\r\f\f\n \f€\f‚ \b € €€Š\f €‚\f\f  ˆ\n\f \f\f… €\bŠ‹‹  €€ €Š    \f‹  \f‚\fƒ\f\f\f\f\nŠ  \f\n\f \n\fˆ€\f ƒ\f  \f‹Š\n\f \fŠ €Š€ \f€\f \f€ \f\f  \fŠ €„\r\f\f†ˆ€ Š \f\fˆ\f ƒ\f€ƒ€\f\r€ ‹€\f\r€ €\f\b\r€‚\f\f €‚\f\f  \f‚\f \b \f \r\f\fˆ\b\b\f€  €„ˆ\b† \f ‚€\r\fŠ  ƒ\fŠ€\f\b‚\f ƒ\f \bƒ\f \b\f  \f€‡  €€ €€‹\f \r\r\f€ \b­ƒ\f\n  €\f\n\f \f \r€\n\f€\fŠ \fˆ\f † €\rˆ€ \f\r€Š \fˆ  €€ €Š    \fŠ €€€\f†\n\f \fƒ\b‚€\n\f \f€\r\f ƒ\f€\b\f\n  €\f  \fˆ€ƒ\f \nŠ \n\f \n\f \f‹  \f\f  †\f€\n €  \b\fŒŽ„\f\f\f€‡  €€ \b\f €\r \f €\f \n \f\n\b€  \f  \b\b\f†ˆ€ „\f\f€€€\r \bƒ\f ‚\f ƒ€€€\f†Šˆ€  \f\n\f€\r\f\n€ \n \n\b\f  €\f  \f† \b€ƒ\f‹€\b†\f\b \r\f\n€€ €ƒ\fˆ\f\f  €€ \n­  €€ \b\f€ƒ\n€\n\f  \n€ \f ‚€‚\f\f\n€ƒ€€\bŠ\b\fŠŠ  €‚\f ƒ\nˆ\f­ \f \f\n\b\f‹   \f \n\t\b \f \f€€\f\n€\r \f\f\f…    \f €€ Š\f‘‘ \f€\n\f \b€\f\r ˆ€\r \f \bƒ\f \b\f\n€\f \f‰Š€\f  €\b‹\t \f€\n\fƒ‡’ \f ˆ „\f\nƒ\b\f€  \f\n€ƒ\b“€ „\b\f\b€\fƒ€\nŠ\fˆ \n‡ \r\f \bƒ\f ’ \fˆ\f †€ \n€\r “bits on the ground”\f €€€\f  \bŒ‰\f‡ \bƒ\f ƒ\r\fŠ € \f  \f\f  Ž‹\f‚\fˆ€\f Š\f€\f\n\f‡ŠŠ\f€‚\f \bƒ\f  €‚€€\f‚\fƒ\f\f…€’\f\nƒ\b\f\r‚\f \fŒ €‚\fŽ\n\fŠ\f\f†\f \f ƒ\f\n\f\f‚\f €\r€’  \f\r\f†\f\f €\b­€\n €€”\f\n\n‚\f  €\f\n­\f  †ˆ€ \n\bƒ\f€ \f\f\nƒ\b \n\f\f \f \bƒ\f Š  \f‹†\t \f€\n\fƒ\f €\f€ \bƒ\f  \f €Š€  €€ €Š    \f\fƒ\f\r€€\rŠ€\f \n\f ‹\f\fˆ \f€\n\f€\f‰\f €‚\f \n\f €\f\n• ‚€\r €€ Š    \f\bƒ\f \f  €\b–€€\f\b „ˆ\f\n\r\f\f\f\t\f\r‡ ƒ€€€\f \fŠ’ €\f \f \f€‡  €€ \b\f‹\f \n\f \b“The cyber threat to critical infrastructure continues to grow and represents one of the most serious national security challenges we must confront. (…) It is the policy of the United States to enhance the protection and resilience of the Nation’s critical infrastructure and to maintain a cyber environment that encourages efficiency, innovation, and economic prosperity while promoting safety, security, business confidentiality, privacy, and civil liberties. Confront and Conceal. Obama's Secret Wars and Surprising Use of American Power Obama’s Secret Wars and Surprising Use of American PowerŒ\fˆ „ ˆ†Ž‹  „ƒ†• ‚€\r €€ Š    \f\bƒ\f \f  €\b†–‰\f €‚\f \n\f †\fƒ  \b††™™ˆˆˆ‹ˆ€\f\f‹\r‚™\f­ \f­Š’ \f™™™™\f‰\f €‚\f­ \n\f ­€ ‚€\r­  €€ ­€Š    \f­ \bƒ\f \f  €\bš\f\t‹ ˆ\f†•\n \b‡›€\f€€\bƒ\f \f  €\b†–Strategic Studies QuarterlyŒ—€\f Ž‹œ‘‹™™ˆˆˆ‹‹Š‹€™™“™™ˆ€\f ™Š ˆ\f‹\nŠ•\bƒ\f \f  €\b›\f ƒ€€€\fƒ\f ‚\f\n€ \b\f\f\fƒ\b\f\t \r †–‹‹\f \fŠ\f \r\b†\n€ƒ  \b†‚\fƒ\f ž†™™ˆˆˆ‹€‹\r‚™ \n™ƒ€ €™\n™€ŸƒŸ Ÿ‚\f ƒ€€€\f‹\nŠ   \f \n\t\b 3 \n€ƒ€\rŠ  \f ƒ\b\n€\r€\f\n’ ˆ \fŽ‚\fƒ\f\f€€ \b\n\n \f\f\nƒ\b\f… €\bŠˆ\f ™\f   ‚\f\n \f‚\f’‚\f\b\f Š\f \f\b‚\fƒ\f\f\n \f\f\n‹\f  \fŠ  €\f\nŠ€ \f€\f\n\r€ ¡ˆ‹€ \f\n€‚\f  \f€\r\f  \fŠ• €„†–ˆ€  \fƒ „ƒ\fŠ\t \f€\n\fƒ‡\r\r\f\f\n \f\r\b‹—\f‚\f„\f\nƒ €„\n €„\r\f\fŠ\fˆ\f‚\fƒ\f \f ‚€ \f\nŠ\f€€\bŠ\f  \f \f \r€‚€\r€ \r\f‰€€\n \f€\b \f „‹   €€ €Š    \f \f €† €„\r\f\f€ \f €\fŠ Š€ \f‹ €„ƒ\f\fŠŠ\f €‚\f\b\r\f\n¢\fƒ\f  \f€\b€€ \f\f \f \bƒ\f \f  €\bŠ  €€ €Š    \f†\f \f€\f€ € \f‚€\n\f \f €„­ƒ\f\n  †\n\f€\f€\f \n\f \n\fŠ  € \f†\n\b  \f‹Š †Š\f\n\r\r\fˆ\f‡ \f€\r\f \bƒ\f \f  €\bƒ\f€\f \fˆ\f\f \f‹\fƒ\fˆ\b\n\f \nˆ\b\f  \fŠ €„ €\fƒ\f\f\n\bˆ\b€  \f€ €\r€‹\f‚\f \n\f \n\f\r†\f  €\b\f‰\f  \f€”\f\n€\nƒ\f \f  € \b€€ƒ\fŠ\b\f  \f\f€ \b\f \r\f\b\n\f\r ˆ€\r\b\f \f‰€\b‹\f\r€  \f\r\bˆ € €€”\f\b\fˆ€ \f\f \f€ €  \fŒ ‚\fŽ\nŠ  €\f Š\f  €\b \f \f \f‹\f ™ƒ\f\f’  ˆ\n\f \f€€€ˆ\f \f\f €„ˆ\nƒ\f•  \f\f\n–ƒ\f \f€€\r€\f \f\n  \f\f\f  \f€‚\f\n€ Š \bƒ\f  „‹\f€\n\fŠ €„\r\f\f€ \r“€ „\b† \bƒ\f \f€„\f\n€„\f\f€\rˆ\n’ˆ\f€\f‚€ \fˆ\f \f \f‰\r €€ €ˆ\f \f\f‚\f \b\n\bƒ€\f‹‚\f €\f†\fŠ\f €€  \f\n€ \f‰‹ˆƒ\f€\f‚\f\n€ƒ\f \f\n€    \f\b\fŠ \f†\nˆŠ   €Š€€\r€ ‚\f  Š \f“\f \f†€ˆ€ \n\f €€„\f ˆ\n€\f\bƒ\fƒ\f\n\f €‚\fˆ\f\f \f €’  €„\nƒ\f€€\r\f\n €\b•  \f\f\n–€ \f\n\f\f\f‰\f  €\f‹\f€€\f\n \f\n€ €€\f\r€‚\f \bƒ\f  \f“\f \fˆ€\b\f €€”\f€\f€\n\f€’\f\n \f†\nƒ\f \f\f  €\f€€\r€ƒ\f\f€\f\n†\f\bˆ€\f‹€ \f †ˆ€ €ˆ\f \f\b\f€”\f\n Š\f €€”\f\n€ €\n\f†\f \fƒ\b„€\r\fƒ€\f \f‹\f ˆ \n† €„\r\f\f€\f €   ƒƒ€\f  ‹\f \f€\n\f€Š\b\n\b €„€€\r€ \f\r€\f€\f\b \f€ˆ\f  \f Š\f€€ €\n\f‹€\f\n\f €€„\f “€ „\b \f€”\f\n \f „ƒ\f\n€ŠŠ\f \f \fƒ\fˆ\f\f ¥ „ƒ \n¦ \n †•——\f— \r¢\n\bŠ \n €\bƒ\f \f  €\b €\n\f†–š—§ €\rŠ\f \f \f\t \f\f€†™™ˆˆˆ‹­ \f ‹\r‚™  Ÿ\b\f™€ …ˆ\r™ \f\f€™ €\r™­¦ \n ‹\nŠ\f\t\f†•\f „ƒ\b\f  \f \b\t\f\bƒ\f \f  €\b\f€\f‰\f €‚\fŠ €\f  €\b†\fˆ ƒ\f ††™™ˆˆˆ‹\n\fŠ\f\f‹\r‚™   €™   €‹‰¢   €€\n¨£¤•\bƒ\f \f€\r\f \f‹‹‹\f€\r\f\n \fŠ \f\f \r€\r\n€ €€\f‹‹‹†–\f€\r\f \f\n€\f  €\b€ \f†\f\fƒ\f †™™ˆˆˆ‹€€\f‹ \r™€™\n™™\f  \f™\bƒ\f Ÿ\f€\r\f \f‹‰• \f ‚\f€\r€\f †–›\f €”††ˆˆˆ‹‚\f €”‹ ™\f\f  €\f™\nƒ \f  €˜\f‹†•\f ­©\f€€\f \fŠ\f\f \f\f  Exactly how far are we looking into the future? \f \f\f\fŠ \bŒŠ \f‰\f†ƒ\f \f‚\f ƒ€€€\f‚\fƒ\f\f‚\f „\f\n  Š€€\r€Š€\f\n€ \n\fƒ€ €\fŽ†\f €„\f\fŠ   \r\fŠ\f‚€€\r ƒ\f\r \b€  \f ‹ \r\f  \f†ˆ\f \f €„\f\fŠ€\f \r\fŠ\f‚€ \f\f\n € €€”\f€€\r€\fŠŠ †  € €€”€ \r€ƒ\f\r \b€\f\n€\r‹—\f€ \f€ \f\f\n\f\f \f\n€\f €„Š †‡\f‚\f\fƒ€\r\r\f ƒ\f‹\f  \fŠ €„€ \f\n€ €‚\f†€ \f€ €‚\f€ƒŠ \f\f‚\f\n\f€  ‹€„\r\f\f€\f  \fŠ \fƒ\f\n \f\n€ €Šˆ\fŠ \fˆ€„€„\f‹\f \fŠ \f†\b\n\f\f €€Š €„€€ €\b\f \f\n€ €‚\f€\fŠ \f‹Š \f\b† \bƒ\f \f  €\b\f‰\f   \f\b\f €Š\b€Š\f€ €\fŠ \f\n\f  €\n\f €€†\b\f †\n\f \n\f† \f€Š\f€\fŠ\f \r\fŠ\f‚€‹€€\rƒ\f\f €’ €\fŠ \f\f„\f\b €„\f\f­‚\f €’ƒ\f\bˆ€\f‰€ €\b\b€\r‹‚\f\f€€\fŠ\n \n\n\f \r\bŒŽ €\f‚€\n€\bŠ €„\f\f \fƒ\n\f\n€€\f†ƒ\n\fŠŠ\f €€€  ƒ\f ƒ\f‹ \f‰\f†ˆ\f  €\r Š \f“\f \f€„\f\n€ŠŠ\f \f \f€Š\f …\f \f\n\f\r€‚\f \f€Š\f \f\f‚\f \b\f\b\f   \f\f ˆ\f\f„‹\b€\f€\fŠ Three experts, four opinions ƒ\fƒ\f \f ‚\f\fˆ ­ \f€†\f\n€\r  € \f\f€\b\n€€\f\n \f€€  \f€€€ ‹ \f†\f\rƒ€\r €€\f\n€ €Š €„\f\f€ \f‹€ \f\f \f€ €\f€’ \b\nˆ\b\f \f \fŒˆ€ ˆ\n€‚‚\f“€Š\b€\r\f€‚€\n ƒ€€\bŠ\f€\n‚\f  €\f\n \f\n€ €\r\f€  €Ž†€€ˆ\b€ƒ\f\n€€\f \f Š\f €„\f“€‚\f \b\f\f\n\f  €\b \f‰\f €\f \f\nˆ\f ™\f  „€\r\f¬‚\f“\f€†•—\bˆ\n\bƒ\n\b \bƒ\f ­ „¢–\f\b \f\f‰ \f€\r\f €€Š€ƒ\f€‚\f ƒ\f\fƒ€\f\n†€ˆ€\f‹\f \r\f€\f€\fƒ „\f\nƒ\b\fŠ  \f ƒ\f Š \bƒ\f  „\r€  \nŠ\f\b\b\f‚\fƒ\f\f \f \f\n\n\f‹˜ˆ\f‚\f †\f‚\f€\r\fƒ\f Š \bƒ\f  „\r€€€  \f€\r†\f \f€ ƒ€\n\f ­ \f  \f‚\f\r€‚\f\f\f€ŠŠ\f  \b‡ „ € \f‹ \f\f  \fŠ Š  \n\n \nƒ\fƒ…\f €‚\f\b\f \f\nŒˆ€ €\f€\f \fˆ\b €„€\f\f\n \f \f \f\nŽ‹€  \n \f€\r€’ \b\n€ŠŠ\f \f \f\n€ŠŠ\f \f\f  €‚\fŠ \f‚\f \b\f \r\fŠ\f‚€‹ \n€ŠŠ\f \f \f\bƒ\f \f €\fƒ…\f Š\n\fƒ\fˆ\f‚\f\n Š \n  \f Š \f\nˆ€Š‚ ƒ\f \bƒ\f \f  €\bŠ\f \fŠ\f€  \n ‹What are we What are we really referring to when talking about cyber security? The Black Swan Book‚‹®†€\fŒ¥\b«Ž‹­‹™™ˆˆˆ‹­€‹ ™€\r\f™\n™\n\f\f™„Ÿ¥\bŸ«ŸŸ\f  €\bŸ \f\n‹\nŠ›€\f›\f \f\n\f†•°€’\f\n\f  €\b€ˆ\f„\b\f€  €€  ‚\f\bŠ \f\n€†–€Proceedings of the 2009 workshop on New security paradigms workshop†‰Š \n†¯†\f\fƒ\f ž­†®†™™ ‹ ‹ \r™ €€‹ Š¢€\n¨«®‹«®¤†‹«­£‹€€ \fƒ†The Black Swan: The impact of the highly improbableŒ\fˆ „\n˜\f†«Ž‹\f€‰†•\f €\fŠ €\f \f ¯€\f\n— \f\f†–Wired ‚«†€\f†Œ\fƒ  \b†Ž†™™ˆˆˆ‹\nˆ€ \f\f‹\f™ „\t\r\f™\f\f  \f ¯€\f\n— \f\fŸ®‹\nŠ   \f \n\t\b Š \b\f‰\f €‚\fˆƒ\f€‚\f\f\n\f €€ €„\f\f‹ \f‰\f†ˆ\f‰ \b\n\f•\f  €\b  –  ¢\f\r\f\f  ƒ\f€\f \f€\f€ €  ­‚ €€ƒ\fˆ\f\f\f  €\b  \n \f \f\n \bƒ\f \f  €\b€ €\n\f€  €€ €Š    \fª\n€\r€\rŒ€\f Š\f  €\b  Ž\n\f\f \f €\b \f€\f  €\b€ €\n\f‹\f ˆ \n†“€Š\b€\r\f  €\bƒ\f\f ‚\f‚€\n†\n\f€\f  \f \f\n\fŠŠ €\b’\f\n  \f  €\f \f\n\f € ‹\bŠ ˆ \n­„€\r€ \fƒ\f\nƒ\f‚€  \f \fˆ\f­„ˆŠ \bªƒ\f \fƒ\n\b\b\f\n\f€€ Š€ ƒ\f\n\f‹ \f€€†\f‚\f ƒ€€€\f\f‰€\f\nƒ\b‰\f\nƒ\f\f\n Š ‚\f \b\f ‹—€\f€\bƒ\f\f ƒ\f€\b•ˆ€–Š \b€ €\n\f\f €€”\f ŠŠ €„†\f \f \fŠ €€€\f†Š \f‰\f€\f \f €\n \b†ˆ\f \f  \f€‚€ƒ\f‹›\f ƒ€€\b\b€€ƒ\f‚€ \f ƒ\f\f\n \f€ƒ\b€\n\f€Š\b \f‚\f ƒ€€€\f€\b•ˆ€–ƒ\f\f‰€\f\n‹€€\r€†ˆ€\f \f€€\r€\fƒ\f‚\f ƒ€€€\f \f ’‰€\r\f†\b \fŠ\f \f\n•\f  €\bƒ\bƒ  €\b†–ƒ\f\f €\n\f \f\n•ƒ\f  € \f–Š \n\f \n\f‹   € \f \r\f\b\f\f\nƒ\fƒ\n\f\n‹\f €‚\f  €€  ƒƒ€€\b \f€\f€ € \n€\f\r€  \f­\n­ \f“\f \f\n\f‹€\n\f\f\r€  \f€Š \f\n \f“\f \f†\n\f \f\nƒ\b \f €\b‹€„€€\f \f\n€ \b  \fƒ\fˆ\f\fŠ\f\n \f €\b‹—\f \f \f\n \f“\f \f \f\n\f\f €€€ †\fˆ\f€Š €„ƒ\f \f€  €\f‹\f\r€ €„ƒ\fˆ\f\f  \f†\n\f €\rŠ  †\n\fŠŠ\f  ƒ\f\fƒ€\f\n\f€\f ƒ\b\f‰\f €\fŒ\n\f \f\n €\bŽ ƒ\b€€ Œ€Š\f \f\n €\bŽ‹Š\f€\f €€ƒ\f†€€€  €\f„€\f Š €„ƒ\f \f\f€ €  \f\n€ € ƒ\f\n\f‹\f ˆ \n† \f\n€ €ˆ€\f€ƒ€€\bŠ \f€ € ‚\f €’ € \f\f\f \r\b‹—€\f€\bƒ\f\n€Š’ Š  \f  "Maneuver speed" of risk management in critical infrastructure environments ™\r\f \b™\n\n™…™ \bƒ\f ‹\nŠ   \f \n\t\b 7 \n\f‚\f\n™ €\f\f \f  \f €‹\f\f €€ \f Š\f  €\bª€ \nƒ\f‚€\fˆ\f\n\f\f  €\b•\f‚\f \f\f\n–Š  \b\f€€‹\f  \b\fˆ \n†€€€ƒ\f€€\r\f‚\f ƒ€€€\fˆ€€\n\b \f‚\fˆ\f\f„‹\f‰\f \f ‚€ \r€‚\f\f‰\f\fˆ\f €\f\n€\r€€\r\f\f €„Š \b  „ˆ\n\f\f\n\fƒ\f­ \f\n\b\f ˆ ­ \f‹ € \f†€\n €  \b\f€ˆ\f  ƒ\f \f ’\r \f\n\b \f\f \b\f €€\f \fˆ€\nˆˆ\f \f\f€\nˆ†ˆ€ €\b \fŠ\f \f\n\r\f‹Š\f  \f †€ˆ€„\f\f \b\f €Š \f  ’\r € \r\f ƒ\f\n\f†“€\f\r\f\n€\f„ˆ\n€ŠŠ\f \f \f\fˆ \nˆ\f \f\f  €\b \f ƒ\f \f\nˆ€€ €‚€ €”\f\n\f‚€ \f‹\f\f‚\f \f\f\n\f\f\n\f\n \f\n\fˆ‚\f ƒ€€€\f\n \f€  \b\f€€\n \f¡\f  \r€”€‡ˆ€€\r\f  \f\f€ Š  €\f‹\f ˆ \n†€Š\b   \f\f€ Š\fˆ\b\n€ ‚\f \f\n‚\f ƒ€€€\f†\f\f‚€ \fˆ€ˆ\f‚\f \f\f\n \f€\f \f €‹˜ˆ\f‚\f †ƒ\f \f€€\fŠ \f€\f‰  \n€ €\b \r\fŠ \b€ \f‚€ \f€  €€ €Š    \f†\f‰\f\n€\rˆ\fƒ\f\b\n\n\f \n\f€\f \f \f€\rƒ\f \fŠ\f \f“€ \f\n\f€\r\n \f €’ €  \f† \f €‚\f   \bƒ\f \f  €\b€\f  \fŠ   \f‹ˆ\n„\f\f\f\bŠ  \f ƒ\f€\n\f€’\f\n \f\n\f \n\f€\n‚ \f‹€ˆ ˆ€\f€\f \f€€\t \f€\n\fƒ‡\f‰\f €‚\f \n\f †ˆ€  \f€\f \f€Š € €\r†ƒ\f \f \f€\f€\r\f \f ƒ\f\f\f€Š\f \f€  € ˆ\b €‹\f Š €\r \f€\b€\f… €\bŠ\fˆ\f €  €€ €Š    \f†\n\bƒ\f\f‚\f\fˆ€€\f‹‹\f \fŠ˜\f\n\f  €\bˆ \f \f€ƒ\fŠ €€\r\f†ˆ\n‚\f€\n\fˆ\nˆ\f\f €\r€\r€’  \bƒ\f  „ˆ€€\f‹€€ \r\f†\f \r\r\f\f\f€€Š € €\r‹—\f \fˆ €\r€\fˆ€ \f\n€ ƒ\bˆ\bƒ\fŠ  Š\n\f“\f† \f \f\n\fƒ\f \f \f\r€  € €\b‹€\rŠ   \f ƒ\f†\f\f\fˆˆ\f€\f€\f\n \r€”€‚\f€\f\n\f „ƒ\b€\r  €\r €„­ƒ\f\n\f\n\r€\f‹ €\n€€ €„­ƒ\f\n \bƒ\f \f  €\b \f\f\f\n \f ƒ\f€‚\f\n†\f \f € \f€ƒ€€\b  €Ž†\f \b€\f\n\f‚\f\fŠ\f €€ Š    \f\t \f €Œ\tŽ\n \n†\f\n\fƒ€\fŠ  €\f €€\n\f€Š\b  €€ \f‹\f­\t  €\f €„\f\f\fŠ \f\f  € \f\r€\f\f €\r\f \f €‚\f†Š \f‰\f†€€\n\f€Š\b€\r\r\f\f €\r\f“ \f‰ \f\f\n†£¥—€€\r\f€\f  \f €• €€ \f‹–\r\f ‚€\fˆ\f­\t\n \n‚€\r€\f\r \f\n €„€\f€  \n €  \b\f \f\f\n€\r€\n\f‚€ \f \f\f\n  \n€ \f €Š\b€ \f“€\f †‚‚\f† † ƒ \f € \f€\f‹\f\b\f \f \f  €\r\f—€\nˆ\f €\r\b\f\n\n‡‚\f„\f\bƒ \n†€   \n\n €‚\f \f\n‹ € \n €€\n €  \b\f\n\f€  €  \f  €\b \f\r\f\f\fš\f—\f€†Protecting Industrial Control Systems from Electronic ThreatsŒ\fˆ „¥\f\t \f†Ž‹•\f\f \b\f \n € \b\f\bƒ\f \f  €\b—\f„\f\f†–\n€ƒ  \b†¥\b†™™ˆˆˆ‹Š‹ \r™\r™\f €™ƒ‹\nŠ\f€ƒ€€\b\n \nŠ \f\f  € \b\fŠ \f € †– \f € \f€ƒ€€\b  €†š \b††™™ˆˆˆ‹\f  ‹ ™\n ™\n \n™ ™\f€ƒ€€\bŸ\n \nŸ\f\fŸ\f‹\nŠ   \f \n\t\b   €\f €€„€\r† €’ €\b   \f\n\f €\f\f \f‰€\b€\f€\nŠ\f\n\fŠ\f\n\f \n\f\f\f€„\f\fŠŠ\f €‚\f\n\fŠ\f\f‹\f \f‰\f†\fŠˆ€\r€\n\f’€€Š €„­ƒ\f\n\n\f €€„€\rŠ \f\n€‰Š\f\f \fŠ˜\f\n\f  €\b‡€„\f‰€ €„­ƒ\f\n\n\f €€„€\r€\n\f’\f\n\f\n\f\f €€Š  \fŠ € \f\n€ \f\n € €\b\f\f\fŠ €„\n\f\f‰\f \f\n€ Š  \fŠ € €„‹–\fƒ€ €\fƒ\f\n\n\f\n€€\n €„Š \f€„ˆŠ \f\f‚\fŠ„ˆŠ \f“\f \b†„ˆ\n €†„ˆ€\f€\b†Š „ˆ€†ˆ€„ˆ€‚€†\n„ˆ \f“\f \f \f“€’ƒ\f‹\f“\f\b†€Š\f€„™\f \f \f\f €„†\f€„\f  €€\f \r\f\f €„‹€\r\f\f‰\f †\f \f \f\bƒ€\f\n\f €\tƒ€ €ž­\f‚•§€\n\fŠ \f\f– ‚€\n\f \r\f\n \f\fŠ €„\f\f\f\n\r\b‹\r\f\r€\n\f ‚€\n\f\f ‚\f €\n\f †\f\f\n\f\f€\f\n\f€\n€ƒ\b\b\r\f €\f\f € \f€\f \n\f \fŠ\f  ˆ \n\n€Š €„­ƒ\f\n  \f‹\f \f \f\bˆ\b\r\f €„†ƒ€Š \r€”€\f‚€€\f’ \f„€\rƒ€\r€‚\f\f€  €\r €„Œ\n€ €\f \f†‚\f ƒ€€€\f†\n \f“\f \fŽ†€\bƒ\f„€\r\fƒ\f€‚\f\fŠ€ \bƒ\f \f  €\b \f  \f‹\f\f\f†\r\f €\f \f\f‰\f \f\n„\f\n\n\f €€ƒ\f\n\nŒ­ €\f€Š€ \b‚€\n\f\nŽ\f\n\r€\f‹\fƒ\f\f‰\fŠ €„“€’ €\r\fˆ \r€€\f’ € „\f\n†ˆ‡ˆ \f†€ƒ\f \f \f\n\rƒ\f‰\f €\f \f‹‚€\n©‹€†ƒ €€\t‹‹ˆ€€\f\n‚ \f\n\n\f\r \f\f†  \f\f\nŠ „ˆ•§€ Š €‹–„† €\r\r\f €\f†\n \f\r €„\f\n\f\n€Š \f \f €„€\f‚\f \b€\rˆ\fˆ \r€\f­ \f\n’ €  €€Š«­žŒ\nƒƒ\f\n•\f§ \f\f \f€– \f \f \f\bŽ‹\f \n\f\f\f ƒ\f €\r\nˆ\f \f\f\f \f\nˆ€€\fˆ €„Š \f\nƒ\b\fƒ†•\b€\r \f€\f  \f€€  €‹–€\f€\f€\f \f\nƒ\b†•ˆƒ €€€€’ €Š€  ƒ\f ƒ\f†–\nŠ \f \f€”\f\nƒ\b€€\fŠ†•\f\n\r\f  €ˆ\f\f\fƒ\f€\f‚\f\f‚\f \b€\r €\rŠ€‹–\f \f \f\b  \f\n\n \f€\r\f€\fŠ \bƒ\f \f  €\bŠ   €€ €Š    \f†ˆ\f‚\f †\n\n \f€\r\f€ \b’  ‚€\n\f\f\r \f\f\n‚\r\f‹—€\f\f \f \f\b€ €„\f‰€ \n€€†–\f \fŠ˜\f\n\f  €\b€„\f\f €\r€\f\f†\f\fƒ\f †™™ˆˆˆ‹\n‹\r‚™‰€ƒ  \b™\f™\n­ €„­\f‰€ ­‹\nŠ†•§€\n\fŠ \n €\r\f\f‹–\fƒ†The Black Swan†•\f €\fŠ €\f ‹–\f‚\f‹ƒ€„\b†•\bƒ\f \f  €\b \f\r\b\t €\f Š \t€ \b¥„\f \n\f\f €\f†–Journal of National Security Law & Policy‚‘†€\f«Œ\r†Ž‹«œ®‹Cyberspace Policy Review:Assuring a Trusted and Reliant Information and Communications Infrastructure†\f—€\f˜\f†¥\b®†®†™™ˆˆˆ‹ˆ€\f\f‹\r‚™\f™\n \f™\bƒ\f  \fŸ\t€ \bŸ\f‚€\fˆŸ’‹\nŠ  „ƒ†•\f „ƒ\b\f\t \f€\n\f\f  €\b €‡\bƒ\f Š    \f†–—€\r††¥\b®†®†™™ˆˆˆ‹ˆ€\f\f‹\r‚™‚€\n\f™\t \f€\n\f­ƒ­­\bƒ\f \f  €\b±   €•\bƒ\f \f  €\bˆ\f \f †–\f\f Š  \f\r€ \n\f €\n€\f†š \b†™™ €‹ \r™’\f™ƒ€ €™žŸ\fˆ€Ÿ\bƒ\f \f  €\bˆ\f \f Ÿ—\fƒ‹\nŠ Agencies are expected to make sound decisions on unsound (non-scientifically validated) methodologies.   \f \n\t\b €€ˆ€ \b  €\f‚\f†€\f Š \f‚\f€\r\f Šƒ\n€\rŠ \f€\r€ \b€‡\f\f‹\f‚\f \b €\r† \f‚\f\n\b†\f\b \r€ ƒ\f­\fŠŠ   Š \b€\rŠ ƒ\f‹\fŠˆ€\r\f €†ˆ\f€\f \f\fƒ€  € €\f€\r\r€\n\f€ \b­ƒ\f\n  \f\n\n \f\f \bƒ\f  \f€  €€ €Š    \fˆ€ \fŠ\f €\r\f  \fŠ €„‹\f€\f€Š   € ‚€\n\fŠ \fˆ „Š  \f­ˆ \n \f €‚\f €\b\fƒ \f„\fƒ€Š\n€ €\r \f€\r\f \f \bƒ\f  €„\n\b\f‰ \fŠ \n€\r€\r‹\f \f\f € €\f†ˆ€ \r\f\f Š \f  €€ €Š    \f \bƒ\f  \f € €\n† \f\f†\f € \bŠ€€ ‚\f \f € ªˆ†Š   € \fŠŠ ’‰\n\f€\r‚\f ƒ€€€\fª\n \f\f†\f ‚€‚\f\f \f  \f € €\r \bƒ\f \f  €\b\fŠŠ •  €€ –\b\f‹ †€‡politics, Principle 1: Primacy of Politics Critical infrastructure protection is a political issue, it doesn't necessarily generate profit.  \fˆ\nƒ\fƒ\f\f’ €Š \f\f \b\n €\r\b‹ \b€\n€‚€\nƒ€\fˆ\f €  €€ €Š    \f† \f €\r\r€ \bƒ\f  „ \bƒ\f…€’\f\nƒ\b\f \f Š€ ‚€\r\fƒ€\f€“ \f \b \f‹ˆ\n€\bƒ\f…€’\f\nƒ\b€ ‚€\r\f € ‡\f  €\b‹˜ˆ\f‚\f †\fƒ…\f €‚\fŠ\b \f  €   €€‰€€”\f’ €  \f‹ ‚€\r€\f  €\b\n\f‡\f \f €\b\bŠŠ€ \n  \f \b‹Š \bƒ\f \f  €\bˆ\nˆ€ƒ „ƒ\f \fƒ \f\f\f† €\fˆ\n‚\fƒ\f\f\n€\r€Š \b\b\f †ˆ€\f\t \f€\n\f‚€\r \fƒ…\f ‹¥\fƒ\f Š\f‹‹\r \f\n€\n‡ \f€”\f€€ˆ\f\f\b \f…\f \f\n\f€\n\fŠƒ€\n€\f ‰ƒ\f\f’Š \fˆ\f €\f\f€\r \bƒ\f \f  €\bƒ\f \f\f\b\n€\n‡ˆ €‚\f\f   €\f\f…\b\f \bƒ\f\f’Š €\b•\n€\r\f €\r€\r‹–€„\f€  Š’ \f  €\b†ˆ „ \fŠ\f\bŒ\f‹\r‹†˜Ž†\f‚€ \f€† \f \f\n €Š‰€ ƒ \f€„\f\f\n€ \f  € \n Œ\f‹\r‹†˜Ž†\f \bƒ\f \f  €\bŠ  €€ €Š    \f€\f \f\f €  ƒ€\f€\fƒ \f €€ \f‹Š €\f \f\fŠ\f\n€  \f€Š\n\f €€„\f € €‚\f   €†€\f \r \fˆ€ƒ\f\n\f‹\f\f \n†\fˆ€€  € €€\f\n \f\r \b \f„€\r\n  \f\f\fˆ „\f €€\fŠ \f €‚\f\f  ‹  Principle 2: Practicality Fix the design vulnerabilities rather than trying to manage them away €€\f\b \f“€ \f\b € ƒ€€€\f‹—€\f\f \f €\f\n\f€Šˆ†ˆ\f \f†\nˆ\f ‚\f ƒ€€€\f \nƒ\f\f‰€\f\n†\nˆ\f \f€\r\n\r\f€\rƒ\f \r\f\b \f €† \f\n€ €€ \f“€ \f\nŠ  €\r \f\n \f‚\f ƒ€€€\f‹  \f\n\f†•€\r  €\f  \b€Š ƒ\f\f  \f €\n\f €€†– \f\n\f² €\f† ƒ\f ¤††™™€ ­ \f ‹­ \f ‹\r‚™€ …ˆ\r™ \f\f€™Š™­­Ÿ  „Ÿ\fŸ Ÿ€\f­  ‹\nŠ€\f¥ €\b \f†\f „\f †\n˜ƒ\r\fˆ †•\f  €\b¥\f € Š \t  \f \b\f†–\n€€ƒ  €\f†\f\fƒ\f «†™™\f\f \r\b‹\r‚™€\f™ \n™’\f™\f \n™ \f\n¥\f\n€™ž­\f  €\bŸ¥\f € ŸŠ Ÿ‹\nŠ•\f\f \b\f ‹–¯\f€ŠŠ\f †š\f †\n¯ \f  Š\f†•§€\n\f\n € \b\fŒŽ\f  €\b†–€€\fŠ\n \n\n\f \r\b\f €\tƒ€ €†\f\fƒ\f «†™™€\n \b €\r‹ \r™\nŠ€\f™ Š­\tž­ž‹\nŠ\n‚€ \t€\f \f­ƒ \f\n\f†¥   € \f †\n§ ‹ € †•\bƒ\f \f  €\b¥\b\tˆ\f  \b\f¥€  \f€\n\f\f€\fŠ‹–IEEE Transactions on Power Delivery‚¤†€\fŒš \bŽ†™™€\f\f\f‰ \f‹€\f\f\f‹ \r™‰™ƒŸ‹…¢ ƒ\f ¨£¤«««†‹¤œ«‹¥ €\b \f†\f „\f †\n˜ƒ\r\fˆ †•\f  €\b¥\f € Š \t  \f \b\f‹–   \f \n\t\b €€\f\f €\b \fˆ\f \f\f‚\f ƒ€€€\f \f\n\f€\r¡ˆŒ €\f \f \n\f€\r   \f €€ ˆ€€\f\n\f\n \f“\f \fŽ† \fˆŠ\n€  \b\f  €\f  \f\n \n ‹€\r  \b\f \n ˆ€ƒ „\n ƒ€­€ƒ\b\n\f€\r\n€€ \f  €\b¡ˆ\b \f€ƒ\f€\r€ƒ\b \bƒ\f  „†\n€\r \f\f  \f \n €\r \f\fŠƒ\f€\r  \fŠ\b „\f\n‹\f\f\f†€\r€\f  \f \n   €‡  €€ \b\f€\f\f€\f ƒ\b\f\r€\r\f‹—€\f \f\n\f ˆ€ƒ „\r \n€\b€„‚\f ƒ€€\b­ \f € Š  \bƒ\f \f  €\bŠ€\f\n†€ \r\f ƒ\f \f \f\n€\f€\n €\n€‹\fƒ€\r\n€ŠŠ\f \f \f€\b\f \f‰€\b‹›\f ƒ€€€\f€\bˆ€ \f‰€\b‹† \r \f€  €\f\nˆ€\r ˆ€ \f‰€\bŠ€ €†\fˆ „†\n \f €‚€\b‹€ \r\f\bƒ\f\fŠ €€\f\nƒ\b„€\r\n‚\r\fŠ¥ \f‡ˆ\n\f \f€\r\n\f €\fŠ\f Š\b€ \f \b‹\f\f\f\nˆ €\f \f\n\fŠ’ €\f \n\fƒ\f\f\f \f\n\f\nƒ\b\fƒ€€\b ˆ\f‚\f  \f\f \b\n \f \b \f\f ƒ\f‰\f†\f—€\nˆ«\f €\r\b\f   \r\b†’\f†\n \f“€ \f€€Š¤\r€\rƒ\b\f \n\n€„ \f\n\f\r€\rƒ\b\f¥‹‡…Š \f\f €\r\b\f†€ \n€\r\b \f€ €  \f€\rˆ „‹\f\n\f „\f \f† \f \f\f\f\f\f \fƒ\f\f’€ \f‰€\b€Š\f\b \fˆ \fŠ\f \n\f­ŠŠˆ€ €\f‚€ƒ\b \f€€\f \fŠŠˆ \f \bƒ\f\f  \f\nŒ\f‚\f\f\b\f  €\bŽˆ€\f\fŠ\f €\n€ \f  €\b• \f‹–\f€\n €\n€†€€  \n€\r\n€\n‡„\f\n‹‚\f \r\f  \f  \f€\f\n\n\b \f  \f \f‰  \f ˆ\f \f€\f\n\b\f \r†\n\f‚\f­Š­\f­€\f\n\f   \f „€“\f\n\n€\f  \f\n\b \f‹\f Š  €\b†‚\f \r\f  \f €  ƒ\f®ž­\b\f\f  \f ˆ€€\f  \f€\rˆ\f \n\f \b†\f\f Š\fƒ\f€\r\f \f\n€„€ƒ\b\f‹—€\n\f \f\fˆ „€\rŠ   \f €\b\n\fŠ  ‚\f€\f \f \f Š \f € \f† \f€\r€ƒ€” \f\fŠŠ\f  \nŠ  \b\fƒ\f€\r\f‰\f\n\f\f \f\n\f€\b ƒ\f‚€\f €€”\f\n\f  \f\r€\f‹‚\f \r\f  \f \f\f\n\f\n€ \f\n € € \f  Œ\f  \f† \f ‚\f †\f\r€\f\f €\r€†\f\f   \f †\f ‹Ž\b€ ‚\f \f€Š\f \b \f‹¥€€Š  \f €\f\n\b†\nƒ \n\fˆ \n ˆ€ƒ\f€\f\n ˆ† \f \f \f‰ \nˆ€ \f\n\b\f\f ‚\f\n\f‚\f \b\f \f€\n\f \n\f‹\f ŠŠ †\b  \b\f€ \f  \b€€ \n€ƒ\f€\f\f\f\n€\r\r\f\f  €  \f\b†ˆ€ \f†\nˆ\f\n€\r‹\f \f\n\f  \r ƒ\f‚\f €€\b •˜ \n\t ƒ\f€†–\f\f   €†‚\fƒ\f †£†™™ˆˆˆ‹ \bƒ\f ‹‹\n‹\r‚™\n ™Ÿ˜ \nŸ\t ƒ\fŸ€‹\nŠ•\f \fŠ\f\f \n€ €€ \b¥\n\b†–¥ \f€\fŠ\f \r\b††™™ˆ\fƒ‹€‹\f\n™€\f€™ \f\f  ™\n€\f™\f­\f\f  € ­\r €\n­‹ \n\n¥€ †¥\f …­­€ †\n‹¥‹¯°\n €†•ˆ \n\f€ €Š\f  €\b¥\f € €ŠŠ\f \f\r\fŠŠ €\b\f†–Journal of Global Research in Computer Science‚†€\fŒ\fƒ  \bŽ†™™…\r  ‹€Š™€\n\f‰‹™…\r  ™ € \f™‚€\fˆ™®\t€\f \f­ƒ \f\n\f† € \f †\n € †•\bƒ\f \f  €\b¥\b\tˆ\f  \b\f‹–™™ˆˆˆ‹\n“‹ ™†  \f\f\n\fƒ  \b‹™™ˆˆˆ‹\n“‹ ™†  \f\f\n\fƒ  \b‹‘†•€\r€\n‡\f  €\b €\f€’ \b€\f\n€š \b€¥€€\f ††–™™‚€\f ‹ ™‘™‘­™‚€\n\f™¤‘®‘†  \f\f\n\fƒ  \b‹   \f \n\t\b  \fŠ  ‚\f€\f \f‹\fƒ\f Š€\n€‚€\n  \f €‚\f \r\fˆ\f €\f‚\f \n \f\n€”\f€“€\f\f\b\r\f\n\f  \f‹\f ˆ \n†\f\f€€ \f€\f  \fƒ\f \fŠ\b\f \f‰€\b†\b\f \f‹\f\b \f€\f  \fƒ\f \f†€ˆ† \bƒ\f \f  €\bˆ\f‚\f   \f €\f€ \n\f€\r‹€\f\r€\f\f €\r \f\r\f\n\f€\r \bƒ\f ­\f  \f \n Š €€\f\n \f‰€\b†Š \r\r\f „\fŠ€ \f‹ Principle 3: Pervasiveness Don't restrict cyber security efforts to "critical" systems \n \b\fƒ\f \f\f\n\n€ŠŠ\f \f\bŠ ­  €€ \b\fˆ\f \f€\f  \f\f\n\f\nˆ\nƒ\f  \fƒ\f‹ \f €€Š‚€\fˆ†€€ \f€\f \b \f €’\f\n­\f  \f\n\f€\r\n\f €  \fƒ \n‹  \b ƒ\f€\fŠ† \f  \f\f €\n \f\n \f\f € \f€ƒ€€\b Š\f\b‹ŠŠ \n\n \f\f \bƒ\f  \f€  €€ €Š    \f\f‚\f ‹‹ \f€\n\f€\n€€ €‹\f‹‹\r \f„\f\n\f ƒ\f€ \f†ƒ\fŠ \f\f\fƒ€\fŠ\f\f \fŠ˜\f\n\f  €\b†ˆ€ €‚€\rƒ€\f\r€€‹ „Š \r \f€\n\f€ €‚€\b ˆ€€\r\f‹ \f‰\f†\f\r \f\n¤\f €\r \bƒ\f \f  €\bƒ\fŠ \f\f€\fˆ†\r€†ƒ €\f\n€Š  €\n €“ \f‹  \f  \nŠŠ€ \f  \n\bƒ\f\f‰€\f\nƒ\b‚€\r\f\f\n€\fª€\r\r\f\f\f € Š  \fˆƒ\f\nŒ\n \n†€ €\f† \f €Ž \f  \fŒ \b€  \f\f\n\f  €\b  ƒ\fŽ‹€\f €\f\n\r\b\b\f\n€  \f€€ \f‹ €\f\n’‰€\f  \fŠ €„€ \f\n€ €‚\f†Š €\r\f ƒ\f\n€\f€€€\f Šƒ€\f\f €  ƒ\fƒ „\f\nƒ\b\f€ € \f‚€\n\f \f\n \n €\r€ \f \f\n­€Š €\n €  \b\f€€†ˆ€ \f €\b \f€\b \f\b\f Š \n €‚\f €‹€\n†€\fŠ­\f‚‚€\rˆ \nŠ \bƒ\f  The reality is that hidden dependencies...are the norm, and require an in-depth analysis by experts to discover. \f €\r\f€‡  €€ \f\bƒ\n\b\f\f‹ \f“€ \f \f€„€\r\f ƒ\f \f € „€\rˆ€\f\r\f\n•ƒ\f  € \f–\n‡ \f\b†…ˆ\f‚\f\f\f€\fŠŠ\f€‚\f€\n\f‹—€\f\f\n\fƒ\f  €€ €Š    \f \f €ƒ\f\f „€\f \fŠ €„\r\f\fŠ  \f\n\f \n\f†\f€ \f€‚\f \bŠƒ\n\fŠ\f€‚\f\nŠŠ\f€‚\f€€ \b \bƒ\f  ƒ€€€\f \f\fŠ \f€…\f’ \f Š\fƒ\n€€ €\n€\n‡ŠŠ\f €€  \n €‚\fŠ\f‹—€€…Š \b\f †€\f\n\fƒ\f \f\f’  \bƒ\f \f ˆ\f €€ \b‹€€ \b \f\n\fŠŠ  \f   €€ €Š    \f  \b\f€€„\fˆ€\f\f\f\n\f\n‹‚\fŠ €€ \b\f \f €‚\f† \f€ \f\n\f\f \f \fŒ  €‚\f\n\fŠ\f\fŽˆ€\f \f \f€\r €\r \f €Œ €‚\f\n\fŠ\f\fŽ€\f“\b“\f€ƒ\f‹€ƒ\f\f ƒ\fˆ\f­  \f\n\nˆ\f­ \f\n\n‚\f  \b…ˆ\f­ \f\n\n‚\f  \b‹¥ \f\r \f†\f\t \f€\n\f \bˆ\bŠ \fŠ €\f Š€\f  €\b€€€ €\f€\f\b \f\b \f „\f\f\b†€\fŠ \f €‚\f\f  \n\f \n\n\n\f‡\fƒ  \fŠ ƒ‚€ \f‹  € \f €\b\n\f  \b\fƒ \n\fŠ \f \f\r€†\b\f\fˆ \f ˆ\f †Š ˆ€  \bƒ\f \f  €\b€ \f\r\f\n \f\n\b† €\f\f \f\n\r\f\f \f ’‹ It is better to be a well-armored and well-armed adversary than just a well-armed adversary. 60 Minutes Weapons of Mass Disruption Wired