Loading...
HomeMy WebLinkAboutCOM 1083.000 1996-1998 ?~CPRepf~.HardCopy 70 f C4, Caw-c,"L http:/lwww.pccip.gov/roport _salahtml ~wTL; li~P~9~ President's Commission on Critical Infrastructure Protection Purchasing the PCCIP Report Critical Foundations: Protecting America's Infrastructures, the report of the President's Commission on Critical Infrastructure Protection, is available in electronic format at this Web site. However, if you would prefer a hard copy of the report, copies are available for purchase from the United States Government Printing Office (GPO). The GPO stock number of Critical Foundations is 040-000-00699-1. The list price of the report is $20. If you would like to purchase a copy of the report, it may be ordered online at the GPO Web site. (You may even go directly to the order form for Critical Foundations.) You may also order the report from the GPO Order Desk by telephone at 1-202-512-1800 or by fax at 1-202-512-2250 the Order Desk is open from 8:00 AM to 4:00 PM Eastern Time, Monday through Friday. The GPO also operates a number of government bookstores throughout the country where you may purchase or order the PCCIP's report. Further information on this and other options for purchasing Critical Foundations is available from an index at the Government Printing Office's Web site. Note: The second printing of this report became available in May 1998. If you unsuccessfully tried to purchase a copy in March or April 1998, it is back in print and available for purchase. 0=wL No, f o 83 V S G 1% No. lit. Yb1 t n,rr._ NW 1 8 11/10/98 1156 AM lofl Executive Summary Critical Foundations Protecting America's Infrastructures "Our responsibility is to build the world of tomorrow by embarking on a period of construction-one based on current realities but enduring American values and interests " - President William 1. Clinton, "ANational Security Strategy for a New Century," May 1997 TlltX'OtlCtln Our national defense, economic prosperity, and quality of life have long depended on the essen- tial services that underpin our society. These critical infrastructures--energy, banking and fi- nance, transportation, vital human services, and telecommunications-must be viewed in a new context in the Information Age. The rapid proliferation and integration of telecommunications and computer systems have connected infrastructures to one another in a complex network of interdependence. This interlinkage has created a new dimension of vulnerability, which, when combined with an emerging constellation of threats, poses unprecedented national risk. For most of our history, broad oceans, peaceable neighbors and our military power provided all the infrastructure protection we needed. But just as the terrible long-range weapons of the Nuclear Age made us think differently about security in the last half of the 20th Century, the electronic technology of the Information Age challenges us to invent new ways of protecting our- selves now. We must learn to negotiate a new geography, where borders are irrelevant and dis- tances meaningless, where an enemy may be able to harm the vital systems we depend on with- out confronting our military power. National defense is no longer the exclusive preserve of gov- ernment, and economic security is no longer just about business. The critical infrastructures are central to our national defense and our economic power, and we must lay the foundations for their future security on a new form of cooperation between government and the private sector. Executive Summary tx. Thy asp for r VdwliM: A satchel of dynamite and a truckload of fertilizer and diesel fuel are known terrorist tools. Today, the right command sent over a network to a power generating station's control computer could be just as devastating as a backpack full of explosives, and the perpetrator would be more difficult to identify and apprehend. The rapid growth of a computer-literate population ensures that increasing millions of people around the world possess the skills necessary to conduct such an attack. The wide adoption of common protocols for system interconnection and the availability of "hacker tool" libraries make their task easier. While the possibility of chemical, biological, and even nuclear weapons falling into the hands of terrorists adds a new and frightening dimension to physical attacks, such weapons are difficult to acquire. In contrast, the resources necessary to conduct a cyber attack have shifted in the past few years from the arcane to the commonplace. A personal computer and a telephone connection to an Internet Service Provider anywhere in the world are enough to cause harm. Growing complexity and interdependence, especially in the energy and communications infra- structures, create an increased possibility that a rather minor and routine disturbance can cascade into a regional outage. Technical complexity may also permit interdependencies and vulner- abilities to go unrecognized until a major failure occurs. We know our infrastructures have substantial vulnerabilities to domestic and international threats. Some have been exploited-so far chiefly by insiders. Although we know these new vulnerabilities place our infrastructures at risk, we also recognize that this is a new kind of risk that requires new thinking to develop effective countermeasures. Coping with increasingly cyber-based threats demands a new approach to the relationship between government and the private sector. Because it may be impossible to determine the nature of a threat until after it has materialized, infrastructure owners and operators-most of whom are in the private sector-must focus on protecting themselves against the tools of disruption, while the government helps by collecting and disseminating the latest information about those tools and their employment. This cooperation implies a more intimate level of mutual communication, accommodation, and sup- port than has characterized public-private sector relations in the past. The Commission has not discovered an immediate threat sufficient to wan-ant a fear of imminent national crisis. However, we are convinced that our vulnerabilities are increasing steadily, that the means to exploit those weaknesses are readily available and that the costs associated with an effective attack continue to drop. What is more, the investments required to improve the situa- tion-now still relatively modest-will rise if we procrastinate. We should attend to our critical foundations before we are confronted with a crisis, not after. Waiting for disaster would prove as expensive as it would be irresponsible. Executive Summary x A Strag for An The Commission recommends several practical measures to realize our vision of a new govern- ment-private sector partnership. The quickest and most effective way to achieve a much higher level of protection from cyber threats is a strategy of cooperation and information sharing based on partnerships among the in- frastructure owners and operators and appropriate government agencies. To facilitate this new relationship between government and industry, new mechanisms will be needed, including sector "clearing houses" to provide the focus for industry cooperation and in- formation sharing; a council of industry CEOs, representatives of state and local government, and Cabinet secretaries to provide policy advice and implementation commitment; a real-time capa- bility for attack warning; and a top-level policy making office in the White House. Other measures are also required. Infrastructure protection must be ingrained in our culture, be- ginning with a comprehensive program of education and awareness. This includes both infra- structure stakeholders and the general public, and must extend through all levels of education, both academic and professional. The federal government must lead the way into the Information Age by example, tightening measures to protect the infrastructures it operates against physical and cyber attack. The government can also help by streamlining and clarifying elements of the legal structure that have not kept pace with technology. Some laws capable of promoting assurance are not as clear or effective as they could be. Others can operate in ways that may be unfriendly to security con- cerns. Sorting them out will be an extensive undertaking, involving efforts at local, state, federal, and international levels. We have offered a number of preliminary legal recommendations in- tended to jump-start this process of reform. Another area where government must lead is in research and development. Some of the basic technology and tools needed to provide improved infrastructure protection already exist, but need to be widely employed. However, there is a need for additional technology with which to protect our essential systems. We have, therefore, recommended a program of research and development focused on those needed capabilities. In summary, all of us need to recognize that the cyber revolution brings us into a new age as surely as the industrial revolution did two centuries ago. Now, as then, our continued security requires a reordering of national priorities and new understanding about our respective roles in support of the national goals. The relationships that have stood us in such good stead through the end of the second millennium must give way to new ones better suited to the third. Executive Summary xi