Resource
Implementation of the Common Risk Model for Dams for Security Assessments of USACE Critical Infrastructure
This paper describes the development and implementation of the Common Risk Model for Dams (CRM-D) methodology for security risk assessments. This methodology, whose implementation represents collaborative efforts between the U.S. Army Corps of Engineers (USACE) and the U.S. Department of Homeland Security, takes into account the unique features of dams and navigation locks and provides a systematic approach for evaluating and comparing risks to terrorist threats across a large portfolio. The methodology, which facilitates the consistent quantification of conditional risk, is relatively simple and easy to implement. Generic configurations are used to characterize the security posture of critical components within a facility, and the corresponding vulnerability assessment is conducted based on pre-selected attack vectors. By combining the resulting vulnerability, expressed as the probability of successful attack (probability that a given type of attack against a specific component will be successful, given it is attempted), with the corresponding consequence estimates, a conditional risk value for each component, as well as the entire facility, may be calculated. The paper details a pilot implementation of the methodology involving several USACE dams. 14 pp. 10 references.