<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JCC</journal-id><journal-title-group><journal-title>Journal of Computer and Communications</journal-title></journal-title-group><issn pub-type="epub">2327-5219</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jcc.2021.98006</article-id><article-id pub-id-type="publisher-id">JCC-111501</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Resilience at the Core: Critical Infrastructure Protection Challenges, Priorities and Cybersecurity Assessment Strategies
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Maryam</surname><given-names>Roshanaei</given-names></name><xref ref-type="aff" rid="aff1"><sub>1</sub></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib></contrib-group><aff id="aff1"><label>1</label><addr-line>Information, Science and Technology Department, The Pennsylvania State University Abington College, Abington, USA</addr-line></aff><pub-date pub-type="epub"><day>02</day><month>08</month><year>2021</year></pub-date><volume>09</volume><issue>08</issue><fpage>80</fpage><lpage>102</lpage><history><date date-type="received"><day>19,</day>	<month>July</month>	<year>2021</year></date><date date-type="rev-recd"><day>23,</day>	<month>August</month>	<year>2021</year>	</date><date date-type="accepted"><day>26,</day>	<month>August</month>	<year>2021</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  The importance of a nation’s infrastructure is a vital core for economic growth, development, and innovation. Health, wealth, access to education, public safety, and helping prepare for global crises like pandemics are all dependent on functioning and reliable infrastructures. In decades, the substantial threats affecting infrastructures globally whether in the form of extreme weather, Covid-19 pandemic, or the threats of state and non-state actors’ hackers, demanded urgency in building resilience infrastructures both during crises and in more stable conditions. At the same time, the adoption of emerging and innovative technologies boosts the development of the infrastructures using information, communication, and technology (ICT) platform. This shift accelerated its evolution toward digitization where interdependent and interconnected cyberspace demands collaborative and holistic strategies in protecting critical and high risks infrastructure assets from a growing number of disruptive cyberattacks. These ever-evolving cyber threats are creating increasingly dangerous and targeted cyberattacks to damage or disrupt the critical infrastructures delivering vital services to government, energy, healthcare, transportation, telecommunication, and other critical sectors. The infrastructure’s high risks assets present serious challenges and are crucial to safety, efficiency, and reliability. Any nation must recognize and determine how to cope with any type of threats to their critical infrastructure as well as the strategies to remain resilient. This article first describes the challenges and the need for critical infrastructure protection including the related global risks challenges. It then reviews the United Nations, the European Union, and the United States’ strategies, priorities, and urgencies of critical infrastructure protection. Subsequently, it surveys the critical infrastructure protection resilience strategies including ISO, IEC, ISA, NIST, CAF and CMM frameworks.
 
</p></abstract><kwd-group><kwd>Critical Infrastructure Protection</kwd><kwd> Critical Information Infrastructure Protection</kwd><kwd> Cybersecurity</kwd><kwd> Operational Technologies</kwd><kwd> Risk Management</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>Understanding the challenge</p><p>Recognizing that the national and economic protection of any nation depends on the reliable functioning of critical infrastructures (CIs), nevertheless, the CIs are arguably now more at risk than ever. The highly digitized and connected of today’s critical infrastructures such as healthcare, government, and other critical sectors have placed them firmly in the sights of domestic and nation-state threats. Historically, the goal of cybersecurity experts is to protect from cyber threats by providing confidentiality, integrity and availability of created, processed, stored, and transmitted IT assets. These cyber threats include internal, external actors and persistent attacks that are often sophisticated, systematic, regimented, and well-funded. In addition, with the responsibility of protecting IT infrastructure assets, cybersecurity experts need to consider the real threats that jeopardize the safety of critical infrastructure operators and their operational technologies (OT). However, addressing the security of OT vulnerabilities and the poorly protected operational system, control system, and connected devices has fallen behind IT infrastructure protection. According to [<xref ref-type="bibr" rid="scirp.111501-ref1">1</xref>] OT is a highly complex industrial control (IC) system such as Supervisory Control and Data Acquisition (SCADA) that manages the programmable systems or a piece of equipment interacting with the physical environment. The IC system or a piece of equipment monitors and controls devices, processes, and events such as power, water, transport, manufacturing, and other essential services. Traditionally, IT assets are considered as the sensitive resources for IT systems, technologies, and business continuity therefore addressing the system vulnerabilities and respond to attacks that are essential. Consequently, these assets’ main concern is to provide confidentiality of sensitive information within IT systems by preventing any unauthorized access. In comparison, OT assets are considered as the power systems, known as cyber operational and physical systems; thus they have different security requirements and constraints in terms of applying security measures as well as providing availability, authentication, authorization, integrity, and safety levels. Additionally, any disruptive incidents on OT assets can harm the safety and reliability of power systems and cause catastrophic repercussions. The repercussion with the greatest consequence of safety as the intentional or accidental mis-operation of OT assets could cause harm or even death. At the same time, the repercussion of reliability is important as it will affect the power system such as generators, breakers, transformers, power, and gas lines [<xref ref-type="bibr" rid="scirp.111501-ref2">2</xref>]. <xref ref-type="fig" rid="fig1">Figure 1</xref> illustrates the different priorities and security requirements of critical infrastructures</p><p>IT and OT systems.</p><p>The need for Critical Information Infrastructures Protection</p><p>The urgent need for Critical Infrastructures Protection (CIP) to strengthen the critical infrastructure operators and their operational technologies is today’s goal to ensure sufficient trustworthiness of systems, products, and services and provide the necessary resilience to support the economy and security interests. Nations should recognize the importance of protecting critical infrastructures against natural disasters, terrorist activities, and now cyber threats. The CIP helps all critical infrastructure sectors to the highest standard and prepares them for disaster preparedness, response, and recovery. According to the Whitehouse fact sheet<sup>1</sup>, the United States of America is recognized as the wealthiest country in the world, yet when it comes to the overall quality of infrastructure protection, it ranks 13<sup>th</sup> globally. In general, nations defined their critical Infrastructure sectors, however, the main four designated lifeline sectors are transportation, water, energy, and communication. Any disruption or loss of one of these sectors will directly affect the security and resilience of numerous sectors and cause harm and catastrophic consequences. While for decades governments and industries prioritized the protection of CI against physical attacks such as sabotage, it is recognized the rapid increase of cyberattacks by increasing the dependency on ICT infrastructures creating more security issues. The main factor in the nation’s CI protection is not only physical disruption or destruction. It is also the accurate operation of CI using ICT-based services. It is important to recognize Critical Information Infrastructures (CII) as a vital component of CI in securing and protecting the availability of critical assets. The CII comprises the critical information and ICT process control systems such as increasing connectivity, remote monitoring, scalability, reliability. The compromised or disturbed CII nevertheless can be initiated by man-made, technical failures, vulnerabilities, and disasters that can jeopardize national security, economic growth, and stability of daily life. Therefore, the need for effective Critical Information Infrastructures Protection (CIIP) strategies, policies, and priorities are significantly essential for most nations. CIIP is considered a subset of CIP, however, governments and industries need to realize that CIP is considered a national security issue whereas CIIP is a global issue. Consequently, private-public sectors require to develop strong partnerships in information sharing and exchange capabilities. As shown in <xref ref-type="fig" rid="fig2">Figure 2</xref>, CII is a set of interconnected ICT infrastructures which are crucial for the safeguarding of vital CI functions such as health, safety, and economy. Any disruption or destruction of ICT functions will result in serious consequences and may cause a major impact on a nation [<xref ref-type="bibr" rid="scirp.111501-ref3">3</xref>].</p><p>In regards to the importance of cybersecurity strategies, nations should adopt CIP and CIIP risk assessment as vital elements of cybersecurity. <xref ref-type="fig" rid="fig3">Figure 3</xref> illustrates the perspective between elements and concepts of CIP, CIIP, and Cybersecurity strategies.</p><p>Critical Infrastructure Threats and Risks</p><p>The Global risks report 2021 [<xref ref-type="bibr" rid="scirp.111501-ref4">4</xref>] recognized cyberattacks among the top five risks along with extreme weather, climate action failure, natural disasters, and infectious diseases risks. The cyberattack risk can cause significant harmful impacts and adverse consequences on technological advances, critical infrastructures, and</p><p>massive exploitation of data on an unprecedented scale. In addition, the Global risks report shows that in the last five years the cyberattacks were among the top five risks which consequently expose the critical infrastructures and their operational technologies subject to risks associated with physical and virtual threats such as natural disasters or risks in cyberspace respectively. <xref ref-type="fig" rid="fig4">Figure 4</xref> illustrates the ranking of global risk in 2021 in terms of likelihood and impact on economic, environmental, geopolitical, societal, and technological risk factors.</p><p>This report shows the advancement of integration and interaction between physical and ICT in critical infrastructures shaped physical infrastructures more reliant using complex operational ICT systems. Consequently, this shift influenced the adversaries’ focuses on exploiting potential cyber vulnerabilities. Due to the nature of interdependencies of the critical infrastructure sectors any damage, disruption, or destruction to one infrastructure sector or subsector can cause cascading effects, create a significant impact on other sectors’ operations.</p><p>Significant critical infrastructures cyber incidents timeline</p><p>In 2021 [<xref ref-type="bibr" rid="scirp.111501-ref5">5</xref>], identified significant cyber-attacks on critical infrastructure sectors globally since 2006. <xref ref-type="fig" rid="fig5">Figure 5</xref> shows the substantial cyber incidents between 2006 to March 2021. The cyber incident dataset are focuses globally on government agencies, defense and critical infrastructures (note that the 2021 data is YTD March).</p><p>[<xref ref-type="bibr" rid="scirp.111501-ref6">6</xref>] collected significant incidents worldwide using publicly available information against the different domains of critical infrastructures from January 1, 2009, to November 15, 2019. The dataset contains 130 incidents that were carried out against critical infrastructure sectors. <xref ref-type="fig" rid="fig6">Figure 6</xref> shows the major incidents in different critical infrastructure sectors recorded between 2009 to 2019.</p><p>Based on the above graph, it is observed that the collected data on disruption of the critical infrastructure sectors are Energy and Transportation sectors. These sectors have significantly the highest spike followed by critical manufacturing and nuclear sectors, respectively. This observation emphasized that the spike is due to recent ransom ware attacks such as WannaCry and wiper malware such as NotPetya in 2017. The key factors of datasets are disruptive cyber-physical incidents as well as cyber-operational incidents. The disruptive cyber-physical incident initiated by the malicious activities executed with state or nonstate threat actors and had disruptive effects in the operational technology (OT) systems, devices, and processes compromising Industrial Control (IC) systems. The other key factor is disruptive cyber-operational incidents where a threat actor performs the malicious activities that disrupt IT systems attached to the ICS or Internet of things (IoT) systems and devices for managing inspection on intelligence preparation of the battlefield (IPB) or stealing intellectual property (IP) for economic commitments. <xref ref-type="fig" rid="fig7">Figure 7</xref> shows the disruptive incidents cases by cyber-physical incidents, cyber-operational incidents, or unknown factors from January 1, 2009, to November 15, 2019.</p><p>The dataset collected by different threat agents that targeted critical infrastructure</p><p>sectors, shown in <xref ref-type="fig" rid="fig8">Figure 8</xref>, suggested that the sectors targeted by the state agents are higher than non-state agents due to the fact the non-state incidents in the cyber domain frequently remaining anonymous.</p></sec><sec id="s2"><title>2. Critical Infrastructure Protection (CIP)</title><p>The United State CIP</p><p>The United State relies on reliable critical infrastructures as a lifeline to their daily lives such as clean water, power, transportation, and communications. The Patriot Act of 2001 [<xref ref-type="bibr" rid="scirp.111501-ref7">7</xref>] redefined the critical infrastructures as a set of assets, systems, operational technologies, and other vital elements in the physical and cyber environments. As the United State critical infrastructure protection became a top priority for the nation, in 2013 the Executive Order 13,636 [<xref ref-type="bibr" rid="scirp.111501-ref8">8</xref>] was initiated for the development of improving critical Infrastructure’s cybersecurity. It directs a policy of the United States “to enhance the security and resilience of the Nation’s critical infrastructures and to maintain a cyber environment that encourages efficiency, innovation, and economic prosperity while promoting safety, security, business confidentiality, privacy, and civil liberties.” [<xref ref-type="bibr" rid="scirp.111501-ref8">8</xref>]. In the U.S, both critical physical and cyber infrastructures are owned and operated by the private sector, federal, state, or regional governments. Following the Executive Order 13,636, in 2014 the Cybersecurity Enhancement Act 2014 (CEA) [<xref ref-type="bibr" rid="scirp.111501-ref9">9</xref>] was authorized through the National Institute of Standards and Technology (NIST) to facilitate and develop a framework for reducing risk to critical infrastructures by 1) Collaboration of public-private on cybersecurity; 2) Cybersecurity Research and Development; 3) Education and Workforce Development; 4) Cybersecurity Awareness and Preparedness; 5) Advancement of Cybersecurity Technical Standards. The framework is to identify “a prioritized, flexible, repeatable, performance based, and cost-effective approach, including information security measures and controls that may be voluntarily adopted by owners and operators of critical infrastructures to help them identify, assess, and manage cyber risks.” Furthermore, in 2015, Executive Order 13,691 [<xref ref-type="bibr" rid="scirp.111501-ref10">10</xref>] was issued to encourage and promote cybersecurity information sharing and to engage the private sectors in sharing information related to cybersecurity risks and disruptive incidents. In the U.S., Critical infrastructure is emphasized on four designated vital components 1) Communication, 2) Energy, 3) Water, and 4) Transportation. Numerous sectors rely on these four vital components. The Cybersecurity and Infrastructure Security Agency (CISA) identified a total of sixteen critical infrastructure sectors<sup>2</sup> and their Sector-Specify Agencies as defined in Presidential Policy Directive-21 [<xref ref-type="bibr" rid="scirp.111501-ref11">11</xref>] and the 2013 National Infrastructure Protection Plan<sup>3</sup>, shown in <xref ref-type="table" rid="table1">Table 1</xref>.</p><table-wrap id="table1" ><label><xref ref-type="table" rid="table1">Table 1</xref></label><caption><title> CISA critical infrastructure sectors and their sector-specify agencies</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Sector-Specify Agency</th><th align="center" valign="middle" >Critical infrastructure sectors</th></tr></thead><tr><td align="center" valign="middle"  rowspan="10"  >Department of Homeland Security (DHS)</td><td align="center" valign="middle" >Chemical Sector</td></tr><tr><td align="center" valign="middle" >Communications Sector</td></tr><tr><td align="center" valign="middle" >Dam Sector</td></tr><tr><td align="center" valign="middle" >Emergency Services Sector</td></tr><tr><td align="center" valign="middle" >Government Facilities Sector</td></tr><tr><td align="center" valign="middle" >Information Technology Sector</td></tr><tr><td align="center" valign="middle" >Transportation system Sector</td></tr><tr><td align="center" valign="middle" >Commercial facilities Sector</td></tr><tr><td align="center" valign="middle" >Critical Manufacturing Sector</td></tr><tr><td align="center" valign="middle" >Nuclear Reactors, Materials &amp; Waste Sector</td></tr><tr><td align="center" valign="middle" >Department of Treasury</td><td align="center" valign="middle" >Financial Services Sector</td></tr><tr><td align="center" valign="middle" >General Services Administration (GSA)</td><td align="center" valign="middle" >Government Facilities Sector</td></tr><tr><td align="center" valign="middle" >Department of Transportation (DOT)</td><td align="center" valign="middle" >Transportation system Sector</td></tr><tr><td align="center" valign="middle" >Department of Defense (DOD)</td><td align="center" valign="middle" >Defense Industrial Base Sector</td></tr><tr><td align="center" valign="middle" >Department of Energy (DOE)</td><td align="center" valign="middle" >Energy Sector</td></tr><tr><td align="center" valign="middle" >Department of Agriculture (USDA)</td><td align="center" valign="middle" >Food &amp; Agriculture Sector</td></tr><tr><td align="center" valign="middle" >Department of Health &amp; Human Services (HHS)</td><td align="center" valign="middle" >Food &amp; Agriculture Sector</td></tr><tr><td align="center" valign="middle" >Environmental Protection Agency (EFA)</td><td align="center" valign="middle" >Water &amp; Wastewater systems sector</td></tr></tbody></table></table-wrap><p>The sixteen CI sectors are interdependent and reliant on each other to provide reliable operations thus any disruption or loss of one of the critical sectors will directly affect the security and resilience of critical infrastructures operators and their operational technologies of other sectors. It is important to identify and understand the interdependencies between the sectors to evaluate the potential risks and vulnerabilities. <xref ref-type="fig" rid="fig9">Figure 9</xref> illustrates the interdependencies of the U.S. critical infrastructure sectors.</p><p>The vast majority of the US critical infrastructure sectors owns and operates by the private sectors. The core commitments of private sector partnerships with the public sectors are essential to foster security and resilience through integrated, collaborative engagement and interaction. The partnerships play a central role in implementing an information sharing and awareness program to disseminate efficiently and effectively the critical threat information, risk mitigation, and other sensitive information from state, local, tribal and territorial governments and international partners. The Department of Homeland Security (DHS) and Cybersecurity and Infrastructures Security Agency (CISA) manage with public and private sector critical infrastructures partners engagement to boost the security and resilience of the US’s critical infrastructures. The partnership between the public and private critical infrastructure sectors<sup>4</sup> is shown in <xref ref-type="table" rid="table2">Table 2</xref>.</p><p>In addition to partnership, facilitating information sharing and awareness programs<sup>5</sup> can be used voluntary and regulatory to provide security and resilience for critical infrastructures. They are a vital key to build a knowledge system to share and maintain crucial threat information, risk mitigation and other sensitive information and assets as shown in <xref ref-type="table" rid="table3">Table 3</xref>.</p><p>Furthermore, a set of guidelines has been provided to form a framework for private and public critical infrastructure sectors for sharing the threat information. This framework aims to facilitate information sharing platforms and accelerate the flow of threat information sharing with private and public critical infrastructures sectors. The vital resources for critical infrastructures security and</p><table-wrap id="table2" ><label><xref ref-type="table" rid="table2">Table 2</xref></label><caption><title> Partnership between the public-private critical infrastructures sectors</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Coordination</th><th align="center" valign="middle" >Description</th></tr></thead><tr><td align="center" valign="middle" >National Infrastructures Protection Plan (NIPP) 2013: Partnering for Critical Infrastructures Security and Resilience</td><td align="center" valign="middle" >Provides an organized partnership approach between the public and the private sector for safeguard, security, and resilience of critical infrastructures</td></tr><tr><td align="center" valign="middle" >Critical Infrastructures Partnership Advisory Council (CIPAC)</td><td align="center" valign="middle" >Provides the operational framework for implementing NIPP partnership structure for jointly engagement in the public and private sector entities to coordinate councils in support of critical infrastructures security and resilience efforts.</td></tr><tr><td align="center" valign="middle" >Critical Infrastructures Cross-Sector Council</td><td align="center" valign="middle" >Provides a forum for CIPAC’s Sector Coordinating Councils (SCCs) to address cross-sector issues and interdependencies.</td></tr><tr><td align="center" valign="middle" >Federal Senior Leadership Council (FSLC)</td><td align="center" valign="middle" >Composed of senior officials from the designated sector-specific agencies and other federal departments and agencies to facilitate enhanced federal communication and coordination across the sectors focused on critical infrastructures security and resilience.</td></tr><tr><td align="center" valign="middle" >State, Local, Tribal, and Territorial Government Coordinating Council (SLTTGCC)</td><td align="center" valign="middle" >Provide a forum for active participants to assure that state, local, tribal, and territorial (SLTT) homeland security partners fully engaged in resilience efforts</td></tr><tr><td align="center" valign="middle" >Regional Consortium Coordinating Council (RC3)</td><td align="center" valign="middle" >Provides a framework to support and promote resilience activities existing regional groups in the public and private sectors.</td></tr></tbody></table></table-wrap><table-wrap id="table3" ><label><xref ref-type="table" rid="table3">Table 3</xref></label><caption><title> Information sharing and awareness programs</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Information sharing and awareness programs</th><th align="center" valign="middle" >Description</th></tr></thead><tr><td align="center" valign="middle" >Traffic Light Protocol (TLP)</td><td align="center" valign="middle" >Set of descriptions to ensure greater sharing of information for directing the availability of sensitive information that can be shared to provide an efficient and regular partnership with the appropriate audience</td></tr><tr><td align="center" valign="middle" >Cyber Information Sharing and Collaboration Program (CISCP)</td><td align="center" valign="middle" >Enables information exchange and the establishment of a community to share public information exchange through reliable public-private partnerships across all critical infrastructures (CI) sectors</td></tr><tr><td align="center" valign="middle" >Information Sharing and Analysis Centers (ISACs)</td><td align="center" valign="middle" >Collect, analyze and disseminate actionable threat information and provide tools to mitigate risks and enhance resiliency to public-private partnerships across all critical infrastructures (CI) sectors</td></tr><tr><td align="center" valign="middle" >Information Sharing and Analysis organization (ISAOs)</td><td align="center" valign="middle" >Similar to ISACs, it gathers, analyzes, and disseminates cyber threat information, but unlike ISACs, ISAOs are not sector-affiliated</td></tr><tr><td align="center" valign="middle" >Automated Indicator Sharing (AIS)</td><td align="center" valign="middle" >Enables the cyber threat indicators and defensive measures to provide assistant in protecting public-private participants</td></tr><tr><td align="center" valign="middle" >Protected Critical Infrastructures Information (PCII)</td><td align="center" valign="middle" >Enables voluntary information sharing between public-private partnerships across all critical infrastructures (CI) sectors</td></tr><tr><td align="center" valign="middle" >Homeland Security Information Network (HSIN)</td><td align="center" valign="middle" >Share sensitive and unclassified information to public-private partnerships across all critical infrastructures (CI) sectors for operations management, evaluate data, send warnings and notifications as well as share the information they need to perform their duties</td></tr><tr><td align="center" valign="middle" >National Cyber Awareness System (NCAS)</td><td align="center" valign="middle" >Develop specific awareness with technical and non-technical audiences by implementing appropriate information including technical warnings, control systems advisories and reports, weekly vulnerability bulletins, and tips on cyber hygiene best practices.</td></tr><tr><td align="center" valign="middle" >National Information Exchange Model (NIEM)</td><td align="center" valign="middle" >Enables efficient risk-informed data exchange across public-private participants</td></tr></tbody></table></table-wrap><p>resilience<sup>6</sup> are shown in <xref ref-type="table" rid="table4">Table 4</xref>.</p><p>The United Nation Security Council (UNSC) CIP resolutions</p><p>The complexity of critical infrastructure protection becomes a complicated process to encompass the entire progression of potential cyberattacks. The</p><table-wrap id="table4" ><label><xref ref-type="table" rid="table4">Table 4</xref></label><caption><title> Critical Infrastructures security and resilience resources</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Resources</th><th align="center" valign="middle" >Description</th></tr></thead><tr><td align="center" valign="middle" >Cybersecurity and Infrastructures Security Agency’s Infrastructures Security division</td><td align="center" valign="middle" >Enable decision-making and information sharing to execute security and resilience activities</td></tr><tr><td align="center" valign="middle" >Information sharing tools</td><td align="center" valign="middle" >Support information sharing within and among the critical infrastructures sectors: Homeland Security Information Network - Critical Infrastructures (HSIN-CI) Infrastructures Protection Gateway (IP Gateway) National Infrastructures Coordinating Center (NICC) National Risk Management Center (NRMC) Protected Critical Infrastructures Information (PCII) Program Protective Security Advisors (PSAs) TRIP wire (Technical Resource for Incident Prevention)</td></tr><tr><td align="center" valign="middle" >Critical Infrastructures Threat Information Sharing Framework</td><td align="center" valign="middle" >Provides vital information and best practices for threat information-sharing entities</td></tr><tr><td align="center" valign="middle" >Critical Infrastructures Information Sharing Environment</td><td align="center" valign="middle" >An individual framework that implements the tools required to provide security partners to distribute vital information in their infrastructure’s security and risk, respond to events, and enhance resilience management</td></tr></tbody></table></table-wrap><p>The UN council Counter-terrorism Committee (CTC) directed by security Council resolutions 1373 (2001) and 1624 (2005) [<xref ref-type="bibr" rid="scirp.111501-ref14">14</xref>] is to coordinate a common UN approach in implementing and preventing terrorist acts. The CTC is</p><p>supported by the Counter-Terrorism Committee Executive Directorate (CTED) to execute the committee’s evaluations on the member state counter-terrorism technical assistance. The UNSC resolutions facilitate the assessment of the effectiveness of member state’s policies to protect critical infrastructures including identifying good practices, deficiencies, and vulnerabilities as well as developing and sharing information analysis of counter-terrorism trends. Subsequently, UNSC resolution 2341 in 2017 [<xref ref-type="bibr" rid="scirp.111501-ref15">15</xref>] adopted the primary resolution on the protection of the critical infrastructures against emerging and rapidly evolving threats posed by cyberattacks and strengthening of States’ capabilities of critical infrastructures. Resolution 2341 (2017) aims with the support of CTED to endorse a necessary step concerning the global awareness and preparedness to cyberattacks on critical infrastructures. The five key elements of the UNSC resolution 2341 (2017), shown in <xref ref-type="fig" rid="fig1">Figure 1</xref>0, are recognized as 1) the awareness emphasizes the strengthening and reinforcing knowledge as well as recognizing the vulnerability and threats on critical infrastructures, 2) the capabilities evaluate the strength of states’ capacities, the partnerships of private and public sectors to mitigate the risk of cyberattacks to a controllable level, 3) the resilience promotes methods of preparation, prevention, crisis management, and recovery to reduce cyberattacks intended to destroy or disable critical infrastructures, 4) the distribution</p><table-wrap id="table5" ><label><xref ref-type="table" rid="table5">Table 5</xref></label><caption><title> UN counter-terrorism four pillars strategy<sup>8</sup></title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Strategy</th><th align="center" valign="middle" >Description</th></tr></thead><tr><td align="center" valign="middle" >Pillars I</td><td align="center" valign="middle" >“Measures to address the conditions conducive to the spread of terrorism”</td></tr><tr><td align="center" valign="middle" >Pillars II</td><td align="center" valign="middle" >“Measures to prevent and combat terrorism”</td></tr><tr><td align="center" valign="middle" >Pillars III</td><td align="center" valign="middle" >“Measures to build states’ capacity to prevent and combat terrorism and to strengthen the role of the United Nations system in that regard”</td></tr><tr><td align="center" valign="middle" >Pillars IV</td><td align="center" valign="middle" >“Measures to ensure respect for human rights for all and the rule of law as the fundamental basis for the Fig.ht against terrorism”</td></tr></tbody></table></table-wrap><p>intensifies an open exchange of operational information between a range of stakeholders such as governmental authorities, law enforcement, foreign partners and private sector owners and operators, 5) the engagement enhances the international and regional sectors to support regional connectivity projects and related cross-border infrastructures.</p><p>UNSC recognized three sectors of critical infrastructure: 1) Energy, 2) Transportation and 3) Water Supply, as well as the vulnerability of critical infrastructures to attacks committed by terrorists in cyberspace. UNSC resolution 2341 (2017) emphasized that terrorist attacks as a distinctive threat to critical infrastructures and urged all states to establish concrete and coordinated efforts in raising awareness and expanding knowledge and understanding to improve preparedness through international cooperation. It is also recognized that threats against critical infrastructures have multiple dimensions. While soft targets consider as sites or regions that are relatively vulnerable to terrorist attacks due to their unrestricted access with limited security, hard targets are intended to make it harder for a terrorist to strike. The classification of such threats caused by these targets depends on their nature, their origin, and the context in which they occur. <xref ref-type="table" rid="table6">Table 6</xref> shows the specific threat classifications to critical infrastructures.</p><p>The European Union (EU) CIP</p><p>The European Council Directive 2008/114/EC was adopted in 2008 as a vital part of the European Program for Critical Infrastructure Protection (EPCIP). The Directive’s purpose is to establish a framework for the identification and designation of critical infrastructure in the EU. The directive defines the European critical infrastructure (ECI) as [<xref ref-type="bibr" rid="scirp.111501-ref16">16</xref>] “an asset, system or part thereof located in the Member States which is essential for the maintenance of vital societal functions, health, safety, security, economic or social well-being of people, and the disruption or destruction of which would have a significant impact in a Member State as a result of the failure to maintain those functions.” The scope of the EPCIP framework is to focus on the assessment and resilience of ECI as well as the need to improve the protection. The directive divides the framework into</p><table-wrap id="table6" ><label><xref ref-type="table" rid="table6">Table 6</xref></label><caption><title> Threat classifications to critical infrastructures</title></caption><table><tbody><thead><tr><th align="center" valign="middle"  colspan="2"  >Threat Classification</th><th align="center" valign="middle" ></th></tr></thead><tr><td align="center" valign="middle"  rowspan="2"  >Nature</td><td align="center" valign="middle" >Physical</td><td align="center" valign="middle" >Destroy, weakening, and intervening in physical structure, mechanical, components, etc.</td></tr><tr><td align="center" valign="middle" >Cyber</td><td align="center" valign="middle" >Manipulate, shut down or limit access to a crucial system, information, or data</td></tr><tr><td align="center" valign="middle"  rowspan="2"  >Origin</td><td align="center" valign="middle" >Insider</td><td align="center" valign="middle" >Actors who linked to the organization, often as employees or suppliers with the ability to gain full or acquire knowledge</td></tr><tr><td align="center" valign="middle" >External</td><td align="center" valign="middle" >Actors who can only gain access utilizing violent acts or espionage</td></tr><tr><td align="center" valign="middle"  rowspan="2"  >Context</td><td align="center" valign="middle" >Isolated</td><td align="center" valign="middle" >Action launched to the same sector, operator, or geographical location</td></tr><tr><td align="center" valign="middle" >Multiple targets</td><td align="center" valign="middle" >Action launched in a manner of campaigns or serial attacks</td></tr></tbody></table></table-wrap><p>three ECI process stages as shown in <xref ref-type="table" rid="table7">Table 7</xref>.</p><p>The directive scope recognizes two CI sectors, 1) Energy and 2) Transport (excluding nuclear energy) as illustrated in <xref ref-type="fig" rid="fig1">Figure 1</xref>1.</p></sec><sec id="s3"><title>3. Cybersecurity Assessment Strategies</title><p>NIST Framework for improving critical Infrastructure’s cybersecurity</p><p>The United State national and economic depends on reliable and functional critical infrastructures. It is recognized that the protection and security of critical</p><table-wrap id="table7" ><label><xref ref-type="table" rid="table7">Table 7</xref></label><caption><title> ECI process under Directive 2008/114/EC</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >ECI process</th><th align="center" valign="middle" >Stages</th></tr></thead><tr><td align="center" valign="middle" >Identification</td><td align="center" valign="middle" >Apply sectoral criteria for critical infrastructures Apply the definition of critical infrastructure, according to Article 2(a) of the directive Apply transboundary element according to Article 2(b) Apply cross-cutting criteria to identify potential ECIs</td></tr><tr><td align="center" valign="middle" >Designation</td><td align="center" valign="middle" >Inform other Member States affected by a potential ECI Critical Infrastructure Warning Information Network (CIWIN) Engage in bilateral/multilateral dialogue with the Member States affected Agree with the Member States affected on ECI Inform European Commission and ECI owner/operator</td></tr><tr><td align="center" valign="middle" >Protection</td><td align="center" valign="middle" >Apply operator security plan (OSP) procedure in accordance with Article 5 and Annex II, and review OSP regularly Designate security liaison officer (Article 6) Report to Commission every 2 years on types of risks, threats and vulnerabilities encountered per ECI sector Classify reports at an appropriate level</td></tr></tbody></table></table-wrap><p>infrastructures became a top priority. In response, NIST [<xref ref-type="bibr" rid="scirp.111501-ref17">17</xref>] released the Cybersecurity Framework in strengthening the resilience of critical Infrastructures by engaging organizations to consider cybersecurity risks as part of their risk assessment and management practices. The NIST Cybersecurity Framework (NIST CSF) was first released in 2014 under executive order 13,636 and updated in 2018. Consequently, the executive order in 2017, required compliance for federal government agencies and entities in their supply chain. The NIST CSF aimed to launch harmonized approach and a common set of practices, standards, goals, and guidelines for managing cybersecurity-related risk. The framework promotes flexible, cost-effective, and prioritized approaches for the protection and resilience of critical infrastructure sectors vital to the US economy and national security. NIST CSF is a voluntary framework that any organization of any size can apply to deliver services and products linked to the nation’s critical infrastructures and the entities in their supply chain. While NIST CSF was responsible for creating a framework to reduce risks in critical infrastructures, the Department of Homeland Security (DHS) launched public and private partnerships to align critical infrastructure owners and operators with existing resources regardless of size or cybersecurity complexity. The Framework’s risk-based and flexible approach is to address cybersecurity complexity attributes including the effect on physical, cyber, and society. The Framework can be implemented in any organization that directly or indirectly relies on the technology including information technology (IT), operational technologies (OT), cyber-physical systems (CPS), or connected devices. Three main components formed the framework: a) Framework core, b) Implementation tiers and c) Framework profiles. The components aim to strengthen the partnership across critical infrastructure sectors in recognizing, prioritizing, and reducing cybersecurity risks including cybersecurity achievable outcomes and their relevant recommendations.</p><p>1) Framework Core</p><p>The Framework Core consists of a set of industry standards, guidelines, and organizational best practices to manage cybersecurity risk that is recognized and identified by stakeholders. The Framework Core has four key elements: 1) Functions form necessary attributes to assist organizations in managing cybersecurity risks, 2) Categories are a subset of a Function that group the cybersecurity issues such as detection methods, asset management, and controls 3) Subcategories are a subset of a Category that assists in achieving the outcomes of each Category such as the investigation of notification from detection systems 4) Information References represent as a section of standards, guidelines, and practices that is frequently used in critical infrastructure sectors. The functions are Identify, Protect, Detect, Respond, and Recover as shown in <xref ref-type="table" rid="table8">Table 8</xref>.</p><p>The functions are facilitating risk management evaluations, addressing threats, and improving the incident post-analysis. <xref ref-type="fig" rid="fig1">Figure 1</xref>2 demonstrates the Framework Core structure.</p><table-wrap id="table8" ><label><xref ref-type="table" rid="table8">Table 8</xref></label><caption><title> Framework core functions</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Functions</th><th align="center" valign="middle" >Description</th></tr></thead><tr><td align="center" valign="middle" >Identify</td><td align="center" valign="middle" >Promote an organizational knowledge in managing cybersecurity risks “system, people, assets, data, and capabilities”</td></tr><tr><td align="center" valign="middle" >Protect</td><td align="center" valign="middle" >Ensure that applicable security control in the safeguarding of availability of critical services</td></tr><tr><td align="center" valign="middle" >Detect</td><td align="center" valign="middle" >Utilize and execute applicable actions to discover the occurrence of a cybersecurity event</td></tr><tr><td align="center" valign="middle" >Respond</td><td align="center" valign="middle" >Apply and achieve detection responses to a cybersecurity incident</td></tr><tr><td align="center" valign="middle" >Recover</td><td align="center" valign="middle" >Perform and execute applicable actions to recover any damaged services promptly caused by a cybersecurity incident</td></tr></tbody></table></table-wrap><p>2) Implementation Tiers</p><p>The Implementation Tiers provide the degree of implementing cybersecurity risk controls. As <xref ref-type="table" rid="table9">Table 9</xref> shows, four tiers measure the degree of organizational decision making on consistency and difficulty in cybersecurity risk management practices as well as identifying responses for the prioritized organization assets that could have potential risk.</p><p>3) Framework Profiles</p><p>The Framework Profile, known as Profile is the association of the functions, categories, and subcategories that measures the security requirement, quantitative and qualitative risks estimated values as well as risk sensitivity, acceptance, and resources to achieve the desired outcomes in the Framework Core.</p><p>ISO/IEC 27000 Series of Standards</p><p>The International Standard Organization (ISO) is an independent, non-governmental international organization that closely works with the International Electrotechnical Commission (IEC), the International Telecommunication Union (ITU), and World Trade Organization (WTO) as well as liaison with United Nations (UN) and its partners. The ISO/IEC Joint Technical Committee (JTC1) developed the ISO/IEC 27,000 family of Standards for information technology</p><table-wrap id="table9" ><label><xref ref-type="table" rid="table9">Table 9</xref></label><caption><title> Implementation tiers and description</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Tiers</th><th align="center" valign="middle" >Implementation Methods</th><th align="center" valign="middle" >Description</th></tr></thead><tr><td align="center" valign="middle"  rowspan="3"  >Tier 1: Partial</td><td align="center" valign="middle" >Risk Management Process</td><td align="center" valign="middle" >Informal practices</td></tr><tr><td align="center" valign="middle" >Integrated Risk Management Program</td><td align="center" valign="middle" >Limited awareness of cybersecurity risk</td></tr><tr><td align="center" valign="middle" >External Participation</td><td align="center" valign="middle" >Sparse cybersecurity coordination</td></tr><tr><td align="center" valign="middle"  rowspan="3"  >Tier 2: Risk Informed</td><td align="center" valign="middle" >Risk Management Process</td><td align="center" valign="middle" >Management approves the risk management practices</td></tr><tr><td align="center" valign="middle" >Integrated Risk Management Program</td><td align="center" valign="middle" >High-level awareness of cybersecurity risk</td></tr><tr><td align="center" valign="middle" >External Participation</td><td align="center" valign="middle" >Shared cybersecurity coordination</td></tr><tr><td align="center" valign="middle"  rowspan="3"  >Tier 3: Repeatable</td><td align="center" valign="middle" >Risk Management Process</td><td align="center" valign="middle" >Formal policies practices</td></tr><tr><td align="center" valign="middle" >Integrated Risk Management Program</td><td align="center" valign="middle" >Organizational wide awareness of cybersecurity risk</td></tr><tr><td align="center" valign="middle" >External Participation</td><td align="center" valign="middle" >Implemented processes, and regular formal coordination.</td></tr><tr><td align="center" valign="middle"  rowspan="3"  >Tier 4: Adaptive</td><td align="center" valign="middle" >Risk Management Process</td><td align="center" valign="middle" >Adaptive policies practices</td></tr><tr><td align="center" valign="middle" >Integrated Risk Management Program</td><td align="center" valign="middle" >Implemented processes, and regular formal coordination as part of the organization culture</td></tr><tr><td align="center" valign="middle" >External Participation</td><td align="center" valign="middle" >Promotes active cybersecurity coordination</td></tr></tbody></table></table-wrap><p>(IT) systems to help and support the best practices for improving organizations’ information security. The ISO/IEC 27000 series of standards were published by ISO and IEC to provide a systematic approach of Information Security Management System (ISMS) for risk management for all organization sizes and sectors. The series consists of inter-related standards that ready for adoption by organizations to develop and implement a framework for managing the security of critical infrastructure assets. <xref ref-type="table" rid="table1">Table 1</xref>0 explains the ISO/IEC 27000 series standards [<xref ref-type="bibr" rid="scirp.111501-ref18">18</xref>].</p><p>As shown in table [<xref ref-type="bibr" rid="scirp.111501-ref10">10</xref>], for effective critical infrastructures cybersecurity risk management, ISO/IEC 27001 and ISO/IEC 27010 parts of ISO/IEC 27000 series are used. While ISO/IEC 27001 is designed to protect the confidentiality, integrity, and availability of their information assets, ISO/IEC 27010 provides controls and guidance for implementing information exchanging and sharing of sensitive information as well as provisioning, maintaining, and protecting organizations or state’s critical infrastructures.</p><p>ISO/IEC 27001</p><p>The first and second versions of ISO 27001 were released in 2005 (ISO/IEC 27001:2005), 2013, respectively and it was reviewed in 2019. Additionally, the ISO/IEC 27001 is supported by the ISO/IEC 27002 code of practice for information security management describing how to implement information security controls for managing information security risks. ISO/IEC 27001 Information Security Management System (ISMS) consists [<xref ref-type="bibr" rid="scirp.111501-ref19">19</xref>] of 1) highlights the importance of achieving objectives of ISMS; 2) provides management leaderships to</p><table-wrap id="table10" ><label><xref ref-type="table" rid="table1">Table 1</xref>0</label><caption><title> ISO/IEC 27000 standards series</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >ISO/IEC 27000 series</th><th align="center" valign="middle" >Standards</th><th align="center" valign="middle" >Information technology—Security techniques—Information security management systems</th></tr></thead><tr><td align="center" valign="middle" >Vocabulary Standards</td><td align="center" valign="middle" >27000</td><td align="center" valign="middle" >Overview and vocabulary</td></tr><tr><td align="center" valign="middle"  rowspan="3"  >Requirement Standards</td><td align="center" valign="middle" >27001</td><td align="center" valign="middle" >Requirements</td></tr><tr><td align="center" valign="middle" >27006</td><td align="center" valign="middle" >Requirements for bodies providing audit and certification of information security management systems</td></tr><tr><td align="center" valign="middle" >27009</td><td align="center" valign="middle" >Requirements</td></tr><tr><td align="center" valign="middle"  rowspan="10"  >Guidelines Standards</td><td align="center" valign="middle" >27002</td><td align="center" valign="middle" >Code of practice for information security controls</td></tr><tr><td align="center" valign="middle" >27003</td><td align="center" valign="middle" >Guidance</td></tr><tr><td align="center" valign="middle" >27004</td><td align="center" valign="middle" >Monitoring, measurement, analysis and evaluation</td></tr><tr><td align="center" valign="middle" >27005</td><td align="center" valign="middle" >Information security risk management</td></tr><tr><td align="center" valign="middle" >27007</td><td align="center" valign="middle" >Guidelines for information security management systems auditing</td></tr><tr><td align="center" valign="middle" >TR 27008</td><td align="center" valign="middle" >Guidelines on information security controls</td></tr><tr><td align="center" valign="middle" >27013</td><td align="center" valign="middle" >Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1<sup>a</sup></td></tr><tr><td align="center" valign="middle" >27014</td><td align="center" valign="middle" >Governance of information security</td></tr><tr><td align="center" valign="middle" >TR 27016</td><td align="center" valign="middle" >Organizational economics</td></tr><tr><td align="center" valign="middle" >27021</td><td align="center" valign="middle" >Information security management for inter-sector and inter-organizational communications</td></tr><tr><td align="center" valign="middle"  rowspan="5"  >Sector-Specific Guidelines Standards</td><td align="center" valign="middle" >27010</td><td align="center" valign="middle" >Information security management for inter-sector and inter-organizational communications</td></tr><tr><td align="center" valign="middle" >27011</td><td align="center" valign="middle" >Code of practice for information security controls based on ISO/IEC 27002 for telecommunications organizations</td></tr><tr><td align="center" valign="middle" >27017</td><td align="center" valign="middle" >Code of practice for information security controls based on ISO/IEC 27002 for cloud services</td></tr><tr><td align="center" valign="middle" >27018</td><td align="center" valign="middle" >Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors</td></tr><tr><td align="center" valign="middle" >27019</td><td align="center" valign="middle" >Information security controls for the energy utility industry</td></tr></tbody></table></table-wrap><p><sup>a</sup>ISO/IEC 20000-1:2011, Information technology—Service management—Part 1: Service ISO/IEC 27001, Information technology.</p><p>ISO/IEC 27010</p><p>ISO/IEC 27010 was published in 2012 and had minor editorial changes in 2015. While ISO/IEC 27010:2015 complements ISO/IEC 27001:2013, the ISO/IEC 27010 provides guidance and guidelines on adopting, implementing, meaning information in inter-organizational and inter-sector communications. ISO/IEC 27010 [<xref ref-type="bibr" rid="scirp.111501-ref20">20</xref>] consists of 1) highlighting the Information sharing, management, and supportive entities for communities as well as inter-sector communication, compliance, and communication model and provides the management direction for information security; 2) addressing the information security for organizations and the status change of employment; 3) providing responsibility for assets, information classification and information exchanges protections and physical and environmental security; 4) addressing the access control, cryptographic control, Operational procedures, protection responsibilities, and technical vulnerability management; 5) providing Information security, delivery management, and incident management in supplier relationships; 6) addressing the management of Information security incident management and improvements and the information security continuity and redundancies vii) compliance with legal and contractual requirements and Information security reviews</p><p>ISO 22301</p><p>ISO 22301 was released in 2012 and was reviewed in 2019. ISO 22301 provides the requirements of security and resilience for business continuity management systems. The standard identifies a set of requirements to implement, maintain and improve a management system to safeguard, protect risks and disruptions as well as prepare a response/recovery to any incident. The standard [<xref ref-type="bibr" rid="scirp.111501-ref21">21</xref>] provides four key requirements for implementing business continuity 1) understanding of organization by Planning, implementing, maintaining, and continually improving Business Continuity Management System (BCMS), 2) provide framework and methodology to support compliance with stated business continuity policy, 3) plan and support actions, resources, and awareness to deliver products and services at an acceptable predefined capacity during a disruption, 4) evaluate the monitoring, measurement, and analysis to enhance the business continuity resilience through the effective application of the Business Continuity Management System (BCMS).</p><p>ISA/IEC 62443 series</p><p>The ISA/IEC 62443 series is a series of standards developed by the International Society of Automation (ISA) and International Electrotechnical Commission (IEC) for industrial and critical infrastructures operational technology, including but not restricted to power utilities, water management systems, healthcare, and transport systems. The ISA/IEC 62443 has four categories to assess the cybersecurity risks and recognize the critical systems. <xref ref-type="table" rid="table1">Table 1</xref>1 shows the series categories and their descriptions<sup>9</sup>.</p><p>Cyber Assessment Framework (CAF)</p><p>The United Kingdom (UK)’s National Security Strategy recognized the security, protection, and resilience of the UK’s Critical National Infrastructures (CNI) remains crucial for the functioning of society, such as those associated with energy supply, water supply, transportation, health, and telecommunication. The UK National Cyber Security Center (NCSC) developed the Cyber Assessment Framework (CAF) [<xref ref-type="bibr" rid="scirp.111501-ref22">22</xref>] known as the NCSC CAF collection to provide a set of fourteen cybersecurity and resilience principles for securing CI sectors. NCSC CAF collection adopted the EU Security of Networks &amp; Information Systems (NIS) Directive that aims to raise levels of cybersecurity and resilience of crucial systems across the EU. The CAF collection is intended for use of any organizations that are part of UK Critical National Infrastructures (CNI) or responsible to provide services to CNI sectors. <xref ref-type="table" rid="table1">Table 1</xref>2 provides an overview of the fourteen CAF cybersecurity and resilience principles as well as classifies the</p><table-wrap id="table11" ><label><xref ref-type="table" rid="table1">Table 1</xref>1</label><caption><title> ISA/IEC 62443 Series categories</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Categories</th><th align="center" valign="middle" >Description</th></tr></thead><tr><td align="center" valign="middle" >General documents IEC 62443-1</td><td align="center" valign="middle" >Present essential concepts and secure development lifecycle requirements</td></tr><tr><td align="center" valign="middle" >Policies &amp; Procedures IEC 62443-2</td><td align="center" valign="middle" >Highlights the security measures and system integration</td></tr><tr><td align="center" valign="middle" >System IEC 62443-3</td><td align="center" valign="middle" >Guidance on designing and implementing secure systems levels</td></tr><tr><td align="center" valign="middle" >Component IEC 62443-4</td><td align="center" valign="middle" >Describe a set of requirements to support secured industrial components</td></tr></tbody></table></table-wrap><table-wrap id="table12" ><label><xref ref-type="table" rid="table1">Table 1</xref>2</label><caption><title> CAF cybersecurity and resilience principles</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Objectives</th><th align="center" valign="middle" >Principles</th><th align="center" valign="middle" >Description</th></tr></thead><tr><td align="center" valign="middle"  rowspan="4"  >Objective A Managing security risk</td><td align="center" valign="middle" >A.1 Governance</td><td align="center" valign="middle" >Acceptable policies and processes to approach the security of network and information systems.</td></tr><tr><td align="center" valign="middle" >A.2 Risk management</td><td align="center" valign="middle" >Recognition, evaluation and awareness of security risks to approach risk management.</td></tr><tr><td align="center" valign="middle" >A.3 Asset management</td><td align="center" valign="middle" >Regulating and awareness of all critical systems and/or services required for support</td></tr><tr><td align="center" valign="middle" >A.4 Supply chain</td><td align="center" valign="middle" >Awareness and control of the security risks for the systems that have external dependencies</td></tr><tr><td align="center" valign="middle"  rowspan="6"  >Objective B Protecting against cyber attack</td><td align="center" valign="middle" >B.1 Service protection policies and processes</td><td align="center" valign="middle" >Measuring and communicating acceptable policies and processes to secure critical systems operations.</td></tr><tr><td align="center" valign="middle" >B.2 Identity and access control</td><td align="center" valign="middle" >Awareness, verifying and regulating access to networks and information systems supporting essential functions.</td></tr><tr><td align="center" valign="middle" >B.3 Data security</td><td align="center" valign="middle" >Safeguarding data used in essential functions from adverse actions.</td></tr><tr><td align="center" valign="middle" >B.4 System security</td><td align="center" valign="middle" >Safeguarding critical network and information systems and technology from cyberattack.</td></tr><tr><td align="center" valign="middle" >B.5 Resilient networks and systems</td><td align="center" valign="middle" >Developing resilience against adverse actions.</td></tr><tr><td align="center" valign="middle" >B.6 Staff awareness and training</td><td align="center" valign="middle" >Involving staff to make a positive contribution to the cybersecurity of essential functions.</td></tr><tr><td align="center" valign="middle"  rowspan="2"  >Objective C Detecting cyber security events</td><td align="center" valign="middle" >C.1 Security monitoring</td><td align="center" valign="middle" >Observing and monitoring the potential security problems and the effectiveness of existing security measures.</td></tr><tr><td align="center" valign="middle" >C.2 Proactive security event discovery</td><td align="center" valign="middle" >Identifying anomalous incidents in relevant network and information systems.</td></tr><tr><td align="center" valign="middle" >Objective D Minimizing the impact of cyber security incidents</td><td align="center" valign="middle" >D.1 Response and recovery planning</td><td align="center" valign="middle" >Placing suitable incident management and mitigation processes.</td></tr></tbody></table></table-wrap><p>fourteen objectives, principles with related guidance and reference for CAF collection<sup>10</sup>.</p><p>Cybersecurity Capacity Maturity Model for Nations (CMM) Framework</p><p>The Cybersecurity Capacity Maturity Model for Nations (CMM) framework was developed in 2016 by the Global Cyber Security Capacity Centre (GCSCC) of the University of Oxford to assess, measure, and evaluate the nations’ cybersecurity capacity. The CMM framework [<xref ref-type="bibr" rid="scirp.111501-ref23">23</xref>] is comprised of five Dimensions to measure and evaluate the effectiveness of security, protection, and resilience of national cybersecurity strategies as shown in <xref ref-type="table" rid="table1">Table 1</xref>3.</p></sec><sec id="s4"><title>4. Conclusion</title><p>Conclusion and Future Improvements</p><p>Critical infrastructure is a crucial requirement for any society to survive. This article assessed that CI protection strategies only are effective if security and resilience are seen as critical requirements in CI. This article reviewed the NIST, ISO/IEC, ISA/IEC, CAF, and CMM cybersecurity assessment frameworks and strategies and their common goal of an assessment framework for increasing the effectiveness of cybersecurity capacity. The assessments focus on evaluating the level of the cybersecurity capabilities by fostering best practices, safeguard information, guiding cybersecurity activities, and managing risks within organizations as well as enabling structures to maintain the desire security posture, determining the current status of cyber preparedness, and develop operational resilience. The CI protections frameworks’ future improvement can develop by a measurement system to evaluate the capabilities of assessment methods, measure the effectiveness of the activities and action plans using meaningful indicators on a</p><table-wrap id="table13" ><label><xref ref-type="table" rid="table1">Table 1</xref>3</label><caption><title> CMM framework</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Dimension</th><th align="center" valign="middle" >Description</th></tr></thead><tr><td align="center" valign="middle" >Dimension 1 Cybersecurity Policy and Strategy</td><td align="center" valign="middle" >Evaluate and enhance the level of national cybersecurity strategy and resilience by improving its incident response, cyber defense, and critical infrastructure capabilities.</td></tr><tr><td align="center" valign="middle" >Dimension 2 Cybersecurity Culture and Society</td><td align="center" valign="middle" >Assess and measure the key elements of national cybersecurity awareness and values of cyber-related risks and the trust level</td></tr><tr><td align="center" valign="middle" >Dimension 3 Building Cybersecurity Knowledge and Capabilities</td><td align="center" valign="middle" >Evaluate the level of availability and quality of national cybersecurity awareness, educational and professional training programs.</td></tr><tr><td align="center" valign="middle" >Dimension 4 Legal and Regulatory Frameworks</td><td align="center" valign="middle" >Assess and observes the direct and indirect cybersecurity national legislation including regulatory requirements for cybersecurity, cyber-crime-related legislation, and related legislation.</td></tr><tr><td align="center" valign="middle" >Dimension 5 Standards and Technologies</td><td align="center" valign="middle" >Observe and addresses the effectiveness of cybersecurity technology, standards, and good practices in protecting critical assets of organizations, national infrastructures, and individuals.</td></tr></tbody></table></table-wrap><p>shared platform, shift voluntary and self-assessment methods to a more consistent and comprehensive assessment approach.</p></sec><sec id="s5"><title>Conflicts of Interest</title><p>The author declares no conflicts of interest regarding the publication of this paper.</p></sec><sec id="s6"><title>Cite this paper</title><p>Roshanaei, M. (2021) Resilience at the Core: Critical Infrastructure Protection Challenges, Priorities and Cybersecurity Assessment Strategies. Journal of Computer and Communications, 9, 80-102. https://doi.org/10.4236/jcc.2021.98006</p></sec><sec id="s7"><title>NOTES</title></sec></body><back><ref-list><title>References</title><ref id="scirp.111501-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">U.S. Department of Commerce (2018) Risk Management Framework for Information Systems and Organizations a System Life Cycle Approach for Security and Privacy. Special Publication No. 800-37, Revision 2, National Institute of Standards and Technology, Gaithersburg. https://nvlpubs.nist.gov/Nistpubs/SpecialPublications/NIST.SP.800-37r2.Pdf</mixed-citation></ref><ref id="scirp.111501-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">International Electrotechnical Commission (IEC) (2019) Cyber Security and Resilience Guidelines for the Smart Energy Operational Environment. International Electrotechnical Commission, Geneva.http://www.iec.ch/basecamp/cyber-security-and-resilience-guidelines-smart-energy-operational-environment</mixed-citation></ref><ref id="scirp.111501-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">(2017) GFCE Global Good Practices Critical Information Infrastructure Protection (CIIP). Global Forum on Cyber Expertise, Brussels, 31 May-1 June 2017. https://cybilportal.org/tools/gfce-global-good-practices-critical-information-infrastructure-protection-ciip/</mixed-citation></ref><ref id="scirp.111501-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">World Economic Forum (2021) The Global Risks Report 2021. 16th Edition, World Economic Forum, Cologny.http://www3.weforum.org/docs/WEF_The_Global_Risks_Report_2021.pdf</mixed-citation></ref><ref id="scirp.111501-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Center for Strategic &amp; International Studies (2021) Significant Cyber Incidents since 2006. Center for Strategic &amp; International Studies (CSIS), Washington DC.https://csis-website-prod.s3.amazonaws.com/s3fs-public/210604_Signifi-cant_Cyber_Events.pdf?Ig0rKRzJ9Bc2WS95MJVt1pkZll5eJLE7</mixed-citation></ref><ref id="scirp.111501-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">National Consortium for the Study of Terrorism and Responses to Terrorism (2019) Significant Multi-Domain Incidents against Critical Infrastructure (SMICI) Dataset. National Consortium for the Study of Terrorism and Responses to Terrorism, College Park. http://www.start.umd.edu/pubs/START_UWT_SignificantMultiDomainIncidentsAgainstCriticalInfrastructure_Dec2019.pdf</mixed-citation></ref><ref id="scirp.111501-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Patriot Act of 2001. https://www.justice.gov/archive/ll/highlights.htm</mixed-citation></ref><ref id="scirp.111501-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">Federal Register (2013) Executive Order 13636: Improving Critical Infrastructure Cybersecurity.https://www.federalregister.gov/documents/2013/02/19/2013-03915/improving-critical-infrastructure-cybersecurity</mixed-citation></ref><ref id="scirp.111501-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">Congress.gov (2014) Cybersecurity Enhancement Act 2014 (CEA).https://www.congress.gov/bill/113th-congress/senate-bill/1353/text</mixed-citation></ref><ref id="scirp.111501-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">Federal Register (2015) Executive Order 13691: Promoting Private Sector Cybersecurity Information Sharing.https://www.federalregister.gov/documents/2015/02/20/2015-03714/promoting-private-sector-cybersecurity-information-sharing</mixed-citation></ref><ref id="scirp.111501-ref11"><label>11</label><mixed-citation publication-type="other" xlink:type="simple">(2013) Presidential Policy Directive-21—Critical Infrastructure Security and Resilience. https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/presiden-tial-policy-directive-critical-infrastructure-security-and-resil</mixed-citation></ref><ref id="scirp.111501-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">United Nations Security Council (2001) UNSC Resolution 1373. United Nations Security Council, New York. https://www.unodc.org/pdf/crime/terrorism/res_1373_english.pdf</mixed-citation></ref><ref id="scirp.111501-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">United Nations Security Council (2004) UNSC Resolution 1566. United Nations Security Council, New York. https://undocs.org/S/RES/1566(2004)</mixed-citation></ref><ref id="scirp.111501-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">United Nations Security Council (2005) UNSC Resolution 1624. United Nations Security Council, New York. https://digitallibrary.un.org/record/556538?ln=en</mixed-citation></ref><ref id="scirp.111501-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">United Nations Security Council (2017) UNSC Resolution 2341. United Nations Security Council, New York.https://www.securitycouncilreport.org/atf/cf/%7B65BFCF9B-6D27-4E9C-8CD3-CF6E4FF96FF9%7D/s_res_2341.pdf</mixed-citation></ref><ref id="scirp.111501-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Council of the European Union (2008) Directive 2008/114/EC—The Identification and Designation of European Critical Infrastructures and the Assessment of the Need to Improve Their Protection. Official Journal of the European Union, 51, 75. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32008L0114&amp;from=EN</mixed-citation></ref><ref id="scirp.111501-ref17"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">National Institute of Standards and Technology (2018) Framework for Improving Critical Infrastructure Cybersecurity. National Institute of Standards and Technology, Gaithersburg. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf</mixed-citation></ref><ref id="scirp.111501-ref18"><label>18</label><mixed-citation publication-type="other" xlink:type="simple">International Organization for Standardization (2018) Information Technology—Security Techniques—Information Security Management Systems—Overview and Vocabulary. ISO/IEC 27000, International Organization for Standardization, Geneva.</mixed-citation></ref><ref id="scirp.111501-ref19"><label>19</label><mixed-citation publication-type="other" xlink:type="simple">International Organization for Standardization (2013) Information Technology— Security Techniques—Information Security Management Systems—Requirements. ISO/IEC 27001, International Organization for Standardization, Geneva.</mixed-citation></ref><ref id="scirp.111501-ref20"><label>20</label><mixed-citation publication-type="other" xlink:type="simple">International Organization for Standardization (2015) Information Technology—Security Techniques—Information Security Management for Inter-Sector and Inter-Organizational Communications. ISO/IEC 27010, International Organization for Standardization, Geneva.</mixed-citation></ref><ref id="scirp.111501-ref21"><label>21</label><mixed-citation publication-type="other" xlink:type="simple">International Organization for Standardization (2019) Security and Resilience— Business Continuity Management Systems—Requirements. ISO 22301, International Organization for Standardization, Geneva.</mixed-citation></ref><ref id="scirp.111501-ref22"><label>22</label><mixed-citation publication-type="other" xlink:type="simple">National Cyber Security Center (2019) Cyber Assessment Framework V3.0. National Cyber Security Center, London. https://www.ncsc.gov.uk/information/cyber-assessment-framework--caf--changelog</mixed-citation></ref><ref id="scirp.111501-ref23"><label>23</label><mixed-citation publication-type="other" xlink:type="simple">Global Cybersecurity Capacity Centre (2021) Cybersecurity Capacity Maturity Model for Nations (CMM) Report. Global Cybersecurity Capacity Centre, Oxford.https://cybilportal.org/wp-content/uploads/2021/03/CMM2021-Edition-March-2021.pdf</mixed-citation></ref></ref-list></back></article>