My Account Log in

1 option

Identifying and Prioritizing Systemically Important Entities : Advancing Critical Infrastructure Security and Resilience / John Bordeaux, Jonathan W. Welburn, Sasha Romanosky, Benjamin Boudreaux, Aaron Strong, Shannon Prier, Cheryl K. Montemayor, Jhacova Williams, Jessica Welburn Paige, Michael J. D. Vermeer, Zev Winkelman.

RAND Reports Available online

View online
Format:
Book
Author/Creator:
Bordeaux, John, author.
Welburn, Jonathan W., author.
Romanosky, Sasha, author.
Boudreaux, Benjamin, author.
Strong, Aaron, author.
Prier, Shannon, author.
Montemayor, Cheryl K., author.
Williams, Jhacova, author.
Paige, Jessica Welburn, author.
Vermeer, Michael J. D., author.
Winkelman, Zev, author.
Contributor:
Rand Corporation. Homeland Security Operational Analysis Center.
Rand Corporation.
National Risk Management Center (U.S.)
Language:
English
Subjects (All):
Computer security--United States.
Computer security.
Computer networks--Security measures--United States.
Computer networks.
Infrastructure (Economics)--United States.
Infrastructure (Economics).
Cyberterrorism--United States--Prevention.
Cyberterrorism.
Communication Systems.
Cybersecurity.
Data Science.
Terrorism Risk Management.
Computer networks--Security measures.
Cyberterrorism--Prevention.
United States.
Local Subjects:
Communication Systems.
Cybersecurity.
Data Science.
Terrorism Risk Management.
Other Title:
Identifying and Prioritizing Systemically Important Entities
Place of Publication:
RAND Corporation 2023
Summary:
In response to the mounting specter of systemic cyber risks, the Cyberspace Solarium Commission recommended that Congress codify the concept of Systemically Important Critical Infrastructure—later renamed Systemically Important Entities (SIEs)—and that the Cybersecurity and Infrastructure Security Agency (CISA) be resourced to identify SIEs and support in the mitigation of their risks to support a broader national strategy of layered deterrence. In support of the CISA National Risk Management Center (NRMC), this report clarifies the concepts of SIEs and introduces a data-driven methodology for their identification and prioritization. Specifically, the authors identify SIEs by their potential to affect national critical functions (NCFs) and prioritize SIEs by measures of their size and interconnectedness. This report builds on existing work regarding Critical IT Products and Services and extending the researchers' analysis to federal agencies and firms that install potentially vulnerable software, in addition to firms that write software. This report further documents systemic risks and cyber risks in software supply chains, past and ongoing analytical support to CISA, and current limitations, and it outlines a path for future work.
Contents:
Chapter One: Introduction
Chapter Two: Background and Motivation on Systemic Importance
Chapter Three: Systemically Important Entities : Identification and Prioritization
Chapter Four: Systemic Cyber Risk
Chapter Five: Future Research
Appendix A: Systemic Importance Analytic Model
Appendix B: Cybersecurity and Infrastructure Security Agency Strategic Intent and National Risk Management Center Missions and Objectives
Appendix C: Cyber Data and Software Dependencies
Appendix D: Analytical Support for the Cybersecurity and Infrastructure Security Agency.

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account