The UK Critical National Infrastructure is critically dependent on digital technologies that provide communications, monitoring, control, and decision-support functionalities. Digital technologies are progressively enhancing efficiency, reliability, and availability of infrastructure, and enabling new benefits not previously available. These benefits can introduce vulnerabilities through the connectivity enabled by the digital systems, thus, making it easier for would-be attackers, who frequently use socio-technical approaches, exploiting humans-in-the-loop to break in and sabotage an organization. Therefore, policies and strategies that minimize and manage risks must include an understanding of operator and corporate behaviors, as well as technical elements and the interfaces between them and humans. Better security via socio-technical security Modelling and Simulation can be achieved if backed by government effort, including appropriate policy interventions. Government, through its departments and agencies, can contribute by sign-posting and shaping the decision-making environment concerning cybersecurity M&S approaches and tools, showing how they can contribute to enhancing security in Modern Critical Infrastructure Systems.
翻译:联合王国关键国家基础设施严重依赖提供通信、监测、控制和决策支持功能的数码技术,数字技术正在逐步提高效率、可靠性和基础设施的可用性,并带来以前没有的新好处。这些好处可以通过数字系统促成的连通性带来脆弱性,从而使潜在袭击者更容易使用社会技术方法,利用流动中的人类破门而入,破坏一个组织。因此,尽量减少和管理风险的政策和战略必须包括对运营商和公司行为以及技术要素和它们与人类之间的界面的了解。如果得到政府努力的支持,包括适当的政策干预,可以通过社会技术安全模型和模拟实现更好的安全。政府通过其部门和机构,可以通过在网络安全M & S方法和工具上签名和塑造决策环境,表明它们如何帮助加强现代关键基础设施系统的安全。