Resource
Application of the Common Risk Model to the Dams Sector: Conditional Risk Analysis and Security Configurations
The Common Risk Model (CRM) is a transparent, mathematically rigorous, and easy to implement method for security risk assessment of critical infrastructure. The quantification of asset vulnerability in the CRM methodology is based on the evaluation of existing security measures (e.g., access control, barriers, etc.) and the resulting identification of the overall security configuration that characterizes the facility or asset under consideration. Several potential defense layers are considered for determination of the security configuration, and they include security measures and protective programs at the national, local, and facility levels. Each security configuration is a function of the attack scenario (ground, water, cyber, etc.), and is associated with a numerical vulnerability, expressed as the probability of successful attack. The probabilities of successful attack are pre-determined using a rigorous expert elicitation process. The vulnerability to each attack type along with the predicted consequences of a successful attack can be combined to yield an overall value for conditional risk, in terms of expected loss in either lives or dollars. This paper provides an overview of the CRM and describes its application to security risk assessment of dams. 8 pp., 3 tables, 1 figure, 1 reference.