Resource
An Integrated Approach for Physical and Cybersecurity Risk Assessment: The USACE Common Risk Model for Dams
The Common Risk Model for Dams (CRM-D), developed by the U.S. Army Corps of Engineers (USACE) in collaboration with the Institute for Defense Analyses and the U.S. Department of Homeland Security, is a consistent, mathematically rigorous, and easy to implement method for security risk assessment of dams, navigation locks, hydropower projects, and appurtenant structures. The methodology provides a systematic approach for independently evaluating physical and cyber security risks across a portfolio of dams, and informing decisions on how to mitigate those risks. The CRM-D can effectively quantify the benefits of implementing a particular risk mitigation strategy and, consequently, enable return-on-investment analyses for multiple physical and cyber security risk mitigation alternatives and facilitate their implementation across a portfolio of dams.
The security posture of critical assets within each facility is characterized using generic security configurations associated with the target. Vulnerability estimates, defined as probabilities of successful attack, are elicited from subject-matter experts for a set of attack vectors against generic security configurations at a dam project. Elicitation is conducted separately for different types of adversary. Vulnerability can be estimated for an attack on a target protected by any combination of generic security configurations. Vulnerability estimates are combined with consequence estimates to calculate a risk value for each attack, conditional on it being selected by adversaries. A decision metric, referred to as exposure, is used to aggregate conditional risk estimates across scenarios. This facilitates the comparison of risks by attack type, by target component, or by any set of scenario conditions. CONT.