110 likes | 302 Views
European Reference Network for Critical Infrastructure Protection The need for experimental security in support of policy making and CIP operators in Europe Dr. Igor Nai Fovino European Commission Joint Research Centre.
E N D
European Reference Network for Critical Infrastructure Protection The need for experimental security in support of policy making and CIP operators in Europe Dr. Igor Nai Fovino European Commission Joint Research Centre
COM 2004/702: Communication from the Commission to the Council and to the European Parliament European Programme for CIP (EPCIP) – DG JLS Green paper, November 2005 Policy package, December 2006 Directive proposal approved, June 2008 – adopted December 2008 “A strategy for a Secure Information Society” – DG INFSO Communication, May 2006 Launch of initiative and new policy package, 2008 European Critical Energy and Transport Infrastructures – DG TREN Communication, March 2007 POLICY CONTEXT Comunicazione su CIP per una strategia europea comune contro attacchi terroristici ad infrastrutture critiche - Valore network comune su C.I. - Riduzione delle Vulnerabilita’ - Rafforzamento delle politiche comuni di CIP in Europa - Sussidiarieta’, Complementarieta’, Dialogo con gli operatori
Vulnerabilities, threat means, attack processes Potential countermeasures Benchmarking of systems How to validate and verify standards, best practices, guidelines etc. EUROPEAN STAKEHOLDERS NEED TO KNOW MORE ABOUT
Real-world data From the vendors of the critical systems and the security-related systems From the critical infrastructure operators Data from desktop simulations and simulated environments Computer simulations and laboratories Data from experimental security test platforms and ranges Data obtained from realistic environments EXISTING SOURCES OF DATA
Laboratories & facilities… ….have to be able to emulate realistic settings ….have to be designed to be capable of handling extreme security situations that might involve the disruption/destruction of components ….need dedicated highly qualified personnel, with specific knowledge of the operational conditions of critical infrastructures A DEDICATED INITIATIVE NEEDED FOR EXPERIMENTAL SECURITY FEDERATING EUROPEAN CAPACITIES
Modelling: -Technical systems Structure, topology Functions Behaviour -Security Vulnerabilities Threats Attacks Interdependencies LINKS MODELS-EXPERIMENTS Experiments: -Reproduction of hazards/threats -Reproduction/ emulation of technical systems -In-the-loop simulation Data, States, Scenarios, Models for simulation Verification, Validation – Shortcomings in abnormal conditions
The concept of a European Reference Network for Critical Infrastructure Protection (ERN-CIP) was presented to the Commission in October 2007 Presented to the CIP National Contact Points in December 2007 DG JLS consulted with countries and informally with industry, receiving support Included in the European Programme for CIP work programme for 2009 THE LAUNCH OF ERN-CIP
Scope To conduct in the period May 2009-May 2010 the preparatory phase of the activity “Establishment of a voluntary EU reference network for critical infrastructure protection” Objective To prepare a detailed project plan for establishing the ERN-CIP and an implementation roadmap for the years to come. ERN-CIP TASK FORCE
BRIEF OUTLINE OF THE ERN-CIP PROCESS MS requirements, priorities & capabilities (facilities) Strategic Info on National visits to the MS’s Basis for the proposal work, also for setting up the expert group Input regarding future.. ...Organisation, procedures & protocols Detailed project proposal & implementation roadmap
CONTACT marcelo.masera@jrc.ec.europa.eu +39 0332 78 9238