The assignment is attached with instructions


Module 3 - Case

PHYSICAL SECURITY THREATS TO OUR CRITICAL INFRASTRUCTURE

Assignment Overview

Transitioning from cybersecurity to physical security, this module examines how our nation's critical infrastructure is affected by the vulnerable cyber technology that controls its daily functions.

In his 2012 Defcon 20 cybersecurity conference presentation, Dan Tentler, founder of the San Diego-based information security consulting firm AtenLabs, shared screenshots of dozens of connected devices he could find on the Internet using a laptop and browser. He was able to access several critical infrastructure systems, showing that they were vulnerable to cyber-attack. His presentation vividly demonstrated that the Internet was not designed with security in mind.

Network-ready industrial control systems that monitor and control the physical processes of machines have become the instruments that contribute to a threat we call physical security. The machines we rely on to supply energy, drinking water, and safe food are at risk. The potential security weakness of SCADA systems was exposed by a cyber-attack against the Natanz Iran uranium enrichment facility. A computer worm, called Stuxnet, caused the facility's control systems to make the centrifuges spin out of control. Stuxnet, a cyber-weapon that changed modern warfare, does not discriminate between nations; it simply attacks and destroys computer-managed machines. 

References:

Tentler, D. (2012) "Defcon 20 - Dan Tentler - Drinking from the Caffeine Firehose We Know as Shodan." YouTube. Retrieved from: https://www.youtube.com/watch?v=5cWck_xcH64:

Case Assignment

  1. Using three different industries, provide three examples of physical security dangers faced by SCADA (supervisory control and data acquisition) network systems.

  2. After reviewing Presidential Policy Directive 21 (PPD-21), discuss a national policy to strengthen and maintain secure, functioning, and resilient critical infrastructure. What is resilient infrastructure? Provide two examples of how this concept protects people and property.

Assignment Expectations

Support your work with peer-reviewed, government, and subject matter expert sources. Your paper will not be longer than 5 pages (excluding cover sheet and reference page).

Here are the provided references:

PHYSICAL SECURITY THREATS TO OUR CRITICAL INFRASTRUCTURE

Required Reading

Amin, M. (2010). Securing the electricity grid. The BRIDGE (Spring). Retrieved from http://www.massoud-amin.umn.edu/publications/Securing-the-Electricity-Grid.pdf. Read especially pp. 15 – 17 where SCADA is mentioned.

Andres, R. (2015). Don’t ignore cyber threats to power infrastructure. Power. 159(1) 56. Retrieved from the Trident Online Library.

Henrie, M. (2013). Cyber Security Risk Management in the SCADA Critical Infrastructure Environment. Engineering Management Journal, 25(2), 38-45. Retrieved from the Trident Online Library.

Logan, B. (2015). Pandora's net. Mechanical Engineering, 137(1), 28-33. Retrieved from TUI Online Library.

The Strategic National Risk Assessment in Support of PPD 8: A Comprehensive Risk-Based Approach toward a Secure and Resilient Nation. (2011). Strategic National Risk Assessment. Retrieved from http://www.dhs.gov/xlibrary/assets/rma-strategic-national-risk-assessment-ppd8.pdf

Thilmany, J. (2012). SCADA Security? Mechanical Engineering, 134(6), 26-31. Retrieved from the Trident Online Library.

Required Video

Tentler, D. (2012) "Defcon 20 - Dan Tentler - Drinking from the Caffeine Firehose We Know as Shodan." YouTube. Retrieved from: https://www.youtube.com/watch?v=5cWck_xcH64

Required Websites

Critical Infrastructure Sectors: http://www.dhs.gov/critical-infrastructure-sectors

History of the Nebraska Avenue Complex (NAC) http://www.dhs.gov/history-nac

Office of Cybersecurity and Communications http://www.dhs.gov/office-cybersecurity-and-communications

Presidential Policy Directive 21 (PPD-21): Critical Infrastructure Security and Resilience advances a national policy to strengthen and maintain secure, functioning, and resilient critical infrastructure. https://www.whitehouse.gov/the-press-office/2013/02/12/presidential-policy-directive-critical-infrastructure-security-and-resil