HomeMy WebLinkAboutCOM 1083.000 1996-1998
?~CPRepf~.HardCopy 70 f C4, Caw-c,"L http:/lwww.pccip.gov/roport _salahtml
~wTL; li~P~9~
President's Commission on Critical Infrastructure Protection
Purchasing the PCCIP Report
Critical Foundations: Protecting America's Infrastructures, the report of
the President's Commission on Critical Infrastructure Protection, is
available in electronic format at this Web site. However, if you would
prefer a hard copy of the report, copies are available for purchase from the
United States Government Printing Office (GPO).
The GPO stock number of Critical Foundations is 040-000-00699-1. The
list price of the report is $20.
If you would like to purchase a copy of the report, it may be ordered online
at the GPO Web site. (You may even go directly to the order form for
Critical Foundations.)
You may also order the report from the GPO Order Desk by telephone at
1-202-512-1800 or by fax at 1-202-512-2250 the Order Desk is open from 8:00 AM to 4:00 PM
Eastern Time, Monday through Friday.
The GPO also operates a number of government bookstores throughout the country where you may
purchase or order the PCCIP's report. Further information on this and other options for purchasing
Critical Foundations is available from an index at the Government Printing Office's Web site.
Note: The second printing of this report became available in May 1998. If you unsuccessfully tried to
purchase a copy in March or April 1998, it is back in print and available for purchase.
0=wL No, f o 83
V S G
1% No.
lit. Yb1
t n,rr._ NW 1 8
11/10/98 1156 AM
lofl
Executive Summary
Critical Foundations
Protecting America's Infrastructures
"Our responsibility is to build the world of tomorrow by embarking on a period of
construction-one based on current realities but enduring American values and interests "
- President William 1. Clinton, "ANational Security Strategy for a New Century," May 1997
TlltX'OtlCtln
Our national defense, economic prosperity, and quality of life have long depended on the essen-
tial services that underpin our society. These critical infrastructures--energy, banking and fi-
nance, transportation, vital human services, and telecommunications-must be viewed in a new
context in the Information Age. The rapid proliferation and integration of telecommunications
and computer systems have connected infrastructures to one another in a complex network of
interdependence. This interlinkage has created a new dimension of vulnerability, which, when
combined with an emerging constellation of threats, poses unprecedented national risk.
For most of our history, broad oceans, peaceable neighbors and our military power provided all
the infrastructure protection we needed. But just as the terrible long-range weapons of the
Nuclear Age made us think differently about security in the last half of the 20th Century, the
electronic technology of the Information Age challenges us to invent new ways of protecting our-
selves now. We must learn to negotiate a new geography, where borders are irrelevant and dis-
tances meaningless, where an enemy may be able to harm the vital systems we depend on with-
out confronting our military power. National defense is no longer the exclusive preserve of gov-
ernment, and economic security is no longer just about business. The critical infrastructures are
central to our national defense and our economic power, and we must lay the foundations for
their future security on a new form of cooperation between government and the private sector.
Executive Summary tx.
Thy asp for r VdwliM:
A satchel of dynamite and a truckload of fertilizer and diesel fuel are known terrorist tools.
Today, the right command sent over a network to a power generating station's control computer
could be just as devastating as a backpack full of explosives, and the perpetrator would be more
difficult to identify and apprehend.
The rapid growth of a computer-literate population ensures that increasing millions of people
around the world possess the skills necessary to conduct such an attack. The wide adoption of
common protocols for system interconnection and the availability of "hacker tool" libraries make
their task easier.
While the possibility of chemical, biological, and even nuclear weapons falling into the hands of
terrorists adds a new and frightening dimension to physical attacks, such weapons are difficult to
acquire. In contrast, the resources necessary to conduct a cyber attack have shifted in the past
few years from the arcane to the commonplace. A personal computer and a telephone connection
to an Internet Service Provider anywhere in the world are enough to cause harm.
Growing complexity and interdependence, especially in the energy and communications infra-
structures, create an increased possibility that a rather minor and routine disturbance can cascade
into a regional outage. Technical complexity may also permit interdependencies and vulner-
abilities to go unrecognized until a major failure occurs.
We know our infrastructures have substantial vulnerabilities to domestic and international
threats. Some have been exploited-so far chiefly by insiders. Although we know these new
vulnerabilities place our infrastructures at risk, we also recognize that this is a new kind of risk
that requires new thinking to develop effective countermeasures. Coping with increasingly
cyber-based threats demands a new approach to the relationship between government and the
private sector. Because it may be impossible to determine the nature of a threat until after it has
materialized, infrastructure owners and operators-most of whom are in the private sector-must
focus on protecting themselves against the tools of disruption, while the government helps by
collecting and disseminating the latest information about those tools and their employment. This
cooperation implies a more intimate level of mutual communication, accommodation, and sup-
port than has characterized public-private sector relations in the past.
The Commission has not discovered an immediate threat sufficient to wan-ant a fear of imminent
national crisis. However, we are convinced that our vulnerabilities are increasing steadily, that
the means to exploit those weaknesses are readily available and that the costs associated with an
effective attack continue to drop. What is more, the investments required to improve the situa-
tion-now still relatively modest-will rise if we procrastinate.
We should attend to our critical foundations before we are confronted with a crisis, not after.
Waiting for disaster would prove as expensive as it would be irresponsible.
Executive Summary x
A Strag for An
The Commission recommends several practical measures to realize our vision of a new govern-
ment-private sector partnership.
The quickest and most effective way to achieve a much higher level of protection from cyber
threats is a strategy of cooperation and information sharing based on partnerships among the in-
frastructure owners and operators and appropriate government agencies.
To facilitate this new relationship between government and industry, new mechanisms will be
needed, including sector "clearing houses" to provide the focus for industry cooperation and in-
formation sharing; a council of industry CEOs, representatives of state and local government, and
Cabinet secretaries to provide policy advice and implementation commitment; a real-time capa-
bility for attack warning; and a top-level policy making office in the White House.
Other measures are also required. Infrastructure protection must be ingrained in our culture, be-
ginning with a comprehensive program of education and awareness. This includes both infra-
structure stakeholders and the general public, and must extend through all levels of education,
both academic and professional.
The federal government must lead the way into the Information Age by example, tightening
measures to protect the infrastructures it operates against physical and cyber attack.
The government can also help by streamlining and clarifying elements of the legal structure that
have not kept pace with technology. Some laws capable of promoting assurance are not as clear
or effective as they could be. Others can operate in ways that may be unfriendly to security con-
cerns. Sorting them out will be an extensive undertaking, involving efforts at local, state, federal,
and international levels. We have offered a number of preliminary legal recommendations in-
tended to jump-start this process of reform.
Another area where government must lead is in research and development. Some of the basic
technology and tools needed to provide improved infrastructure protection already exist, but need
to be widely employed. However, there is a need for additional technology with which to protect
our essential systems. We have, therefore, recommended a program of research and development
focused on those needed capabilities.
In summary, all of us need to recognize that the cyber revolution brings us into a new age as
surely as the industrial revolution did two centuries ago. Now, as then, our continued security
requires a reordering of national priorities and new understanding about our respective roles in
support of the national goals. The relationships that have stood us in such good stead through the
end of the second millennium must give way to new ones better suited to the third.
Executive Summary xi