April 2013

Conference Paper

Risk Assessment Methodology Based on the NISTIR 7628 Guidelines

By:
Abercrombie, Robert K; Sheldon, Frederick T; Hauser, Katie R; Lantz, Margaret W; Mili, Ali
Page Number:
1802-1811
Book Title:
2013 46th Hawaii International Conference on System Sciences
Publication Date:
April 1, 2013
Publisher Location:
IEEE Computer Society, Piscataway, New Jersey, United States of America
Conference Name:
Hawaii International Conference on System Sciences (HICSS-46)
Conference Location:
Wailea, Hawaii, United States of America
Conference Sponsor:
IEEE Computer Society, Unviersity of Hawaii at Manoa

Abstract

Earlier work describes computational models of critical infrastructure that allow an analyst to estimate the security of a system in terms of the impact of loss per stakeholder resulting from security breakdowns. Here, we consider how to identify, monitor and estimate risk impact and probability for different smart grid stakeholders. Our constructive method leverages currently available standards and defined failure scenarios. We utilize the National Institute of Standards and Technology (NIST) Interagency or Internal Reports (NISTIR) 7628 as a basis to apply Cyberspace Security Econometrics system (CSES) for comparing design principles and courses of action in making security-related decisions.