SlideShare a Scribd company logo
<Infrastructure resilience, 2013 Slide 1
Infrastructure resilience
Ian Sommerville
<Infrastructure resilience, 2013 Slide 2
Resilience
• Resilience is the ability of assets, networks
and systems to anticipate, absorb, adapt to,
and recover from a disruptive event or series
of events.
• Resilience is about maintaining the continuity
of a service in the presence of disruptive
events
<Infrastructure resilience, 2013 Slide 3
<Infrastructure resilience, 2013 Slide 4
Pandemic disease
• Pandemic disease is the highest impact
risk because it potentially affects the
whole of a national infrastructure as
people become ill
<Infrastructure resilience, 2013 Slide 5
Cyber attacks
• Cyber attacks that compromise
confidentiality are not likely to have a
major impact on the availability of a
national infrastructure
• But cyber attacks that affect the control
systems are more serious
<Infrastructure resilience, 2013 Slide 6
Risk impact
• Risk impact is related to the extent of
the damage to infrastructure assets
<Infrastructure resilience, 2013 Slide 7
Impact depends on locality
• Local incidents, such as a terrorist
attack on physical infrastructure, have
limited impact because they only affect
a small part of that infrastructure
<Infrastructure resilience, 2013 Slide 8
Organisational infrastructure
• Organisations may be more vulnerable
than physical infrastructure
• Incidents that affect the organisational
infrastructure can have more significant
impact
– Organisations are less likely to be distributed
<Infrastructure resilience, 2013 Slide 9
Risk impact
• Because physical infrastructure is
distributed, failures in one part of a
physical network are localised
– A crack is discovered in one bridge but this does
not affect other bridges in the network
<Infrastructure resilience, 2013 Slide 10
Software vulnerability
• However, software control changes this
– If common elements of an infrastructure are
networked and controlled by the same software, a
failure in one element (especially a malicious
attack) can propagate throughout the network
– Large-scale failures and unavailability therefore
become possible
<Infrastructure resilience, 2013 Slide 11
Infrastructure dependencies
• All infrastructure
elements now
depend on power and
communications
• Failure and
unavailable of these
infrastructures has
the most impact
Photo: creative commons/flickr/anemoneprojectors
<Infrastructure resilience, 2013 Slide 12
Infrastructure vulnerabilities
• Limited
physical
protectio
n
<Infrastructure resilience, 2013 Slide 13
Infrastructure vulnerabilities
• Old/insecure
software
control
systems
Image: http://commons.wikimedia.org/wiki/File:SCADA_PUMPING_STATION_1.jpg
<Infrastructure resilience, 2013 Slide 14
Infrastructure vulnerabilities
• Lack of monitoring systems
• Lack of coordination across
infrastructure elements
<Infrastructure resilience, 2013 Slide 15
Infrastructure vulnerabilities
• Lack of knowledge of infrastructure
state or dependencies
• Lack of knowledge of infrastructure
demand
<Infrastructure resilience, 2013 Slide 16
Achieving resilience
<Infrastructure resilience, 2013 Slide 17
Resistance
Provide protection
against
anticipated events
or attacks
– Flood defences
– Cybersecurity
awareness© Adrian Pingstone 2005
<Infrastructure resilience, 2013 Slide 18
Resistance
• Based on previous experience and
assumptions
• Changing world or external
circumstances may mean that
assumptions are invalid
<Infrastructure resilience, 2013 Slide 19
Reliability
• Infrastructure components should be
designed to operate under a range of
(anticipated) conditions not just
‘normal’ operating conditions
<Infrastructure resilience, 2013 Slide 20
Reliability
• Components, as far as possible, should
be designed for ‘soft’, incremental rather
than catastrophic failure
<Infrastructure resilience, 2013 Slide 21
Digital and analog systems
• Digital systems are more brittle than
analog systems
• Analog systems often fail gradually;
computer-based systems often simply
crash
<Infrastructure resilience, 2013 Slide 22
Redundancy
• The network or system as a whole
should be designed so that there
are backup installations and spare
capacity available.
<Infrastructure resilience, 2013 Slide 23
Redundancy
• Examples
– Computing support should be provided by different
providers in different locations
– Diverse generation capacity for electricity
– Multiple locations for command and control
<Infrastructure resilience, 2013 Slide 24
Response and recovery
• Respond to distruptive events quickly,
limiting the damage as far as possible
and ensuring public safety
<Infrastructure resilience, 2013 Slide 25
Response and recovery
• Plan how to restore services as quickly
as possible in the event of a loss of
capability
• Business continuity planning
• Disaster recovery
<Infrastructure resilience, 2013 Slide 26
Achieving resilience
• Advance planning to draw up contingency plans to
cover anticipated problems
• (a) good design of the network and systems to
ensure it has the necessary resistance, reliability and
redundancy (spare capacity), and
• (b) by establishing good organisational resilience to
provide the ability, capacity and capability to respond
and recover from disruptive events.
<Infrastructure resilience, 2013 Slide 27
Key points
• Critical infrastructure resilience is the ability of
the infrastructure to continue to deliver
essential services during and after a
hazardous event
• Infrastructure resilience depends on planning
for contingencies and effective infrastructure
design
<Infrastructure resilience, 2013 Slide 28
Key points
• Software control of infrastructure systems
potentially increases vulnerability because the
effects of an event may not be localised
• Resilient infrastructure design is based on 4
R’s – resistance, reliability, redundancy, and
recovery

More Related Content

What's hot

Observation site report
Observation site report Observation site report
Observation site report
Sanduli Weerasekara
 
Hazard, vulnerability, risk
Hazard, vulnerability, riskHazard, vulnerability, risk
Hazard, vulnerability, risk
Md Asif Hasan
 
Introduction-construction management_Construction Management (2180611) (Semes...
Introduction-construction management_Construction Management (2180611) (Semes...Introduction-construction management_Construction Management (2180611) (Semes...
Introduction-construction management_Construction Management (2180611) (Semes...
A Makwana
 
02 water demand
02 water demand02 water demand
02 water demand
Akepati S. Reddy
 
Module 9 introduction to disaster risk management
Module 9   introduction to disaster risk managementModule 9   introduction to disaster risk management
Module 9 introduction to disaster risk management
unapcict
 
Resources allocation and resources scheduling_Construction Management
Resources allocation and resources scheduling_Construction Management Resources allocation and resources scheduling_Construction Management
Resources allocation and resources scheduling_Construction Management
A Makwana
 
Sendai framework for_disaster_risk_reduction_2015-2030
Sendai framework for_disaster_risk_reduction_2015-2030Sendai framework for_disaster_risk_reduction_2015-2030
Sendai framework for_disaster_risk_reduction_2015-2030
Cenando Bodanio
 
Understanding and Measuring Urban Resilience: A new UN-Habitat's initiative
Understanding and Measuring Urban Resilience: A new UN-Habitat's initiativeUnderstanding and Measuring Urban Resilience: A new UN-Habitat's initiative
Understanding and Measuring Urban Resilience: A new UN-Habitat's initiative
Global Risk Forum GRFDavos
 
Quality control in construction
Quality control in construction Quality control in construction
Quality control in construction
Thanigaivel Asokan
 
Risk Management in Construction Project
Risk Management in Construction ProjectRisk Management in Construction Project
Risk Management in Construction Project
Dr. Amarjeet Singh
 
Introduction to sustainability
Introduction to sustainabilityIntroduction to sustainability
Introduction to sustainability
Victoria University
 
Terminologies
TerminologiesTerminologies
Terminologies
Prabir Chatterjee
 
Quality control IN CONSTRUCTION
Quality control IN CONSTRUCTIONQuality control IN CONSTRUCTION
Quality control IN CONSTRUCTION
SANJEEV Wazir
 
Economics in Civil Engineering (Or any field of Engineering).
Economics in Civil Engineering (Or any field of Engineering).Economics in Civil Engineering (Or any field of Engineering).
Economics in Civil Engineering (Or any field of Engineering).
Faisal F Rafat
 
Disaster preparedness and hazard reduction processes
Disaster preparedness and hazard reduction processesDisaster preparedness and hazard reduction processes
Disaster preparedness and hazard reduction processesAsh-Leigh
 
Lecture 6: Vulnerability Analysis
Lecture 6: Vulnerability AnalysisLecture 6: Vulnerability Analysis
Lecture 6: Vulnerability Analysis
ESD UNU-IAS
 
Factors affecting Quality of construction projects in India region
Factors affecting Quality of construction projects in India regionFactors affecting Quality of construction projects in India region
Factors affecting Quality of construction projects in India region
Ayush khandelwal
 

What's hot (20)

Observation site report
Observation site report Observation site report
Observation site report
 
Risk Assessment and Reduction
Risk Assessment and ReductionRisk Assessment and Reduction
Risk Assessment and Reduction
 
Hazard, vulnerability, risk
Hazard, vulnerability, riskHazard, vulnerability, risk
Hazard, vulnerability, risk
 
Introduction-construction management_Construction Management (2180611) (Semes...
Introduction-construction management_Construction Management (2180611) (Semes...Introduction-construction management_Construction Management (2180611) (Semes...
Introduction-construction management_Construction Management (2180611) (Semes...
 
02 water demand
02 water demand02 water demand
02 water demand
 
Climate Change and Disaster Management
Climate Change and Disaster ManagementClimate Change and Disaster Management
Climate Change and Disaster Management
 
Module 9 introduction to disaster risk management
Module 9   introduction to disaster risk managementModule 9   introduction to disaster risk management
Module 9 introduction to disaster risk management
 
Resources allocation and resources scheduling_Construction Management
Resources allocation and resources scheduling_Construction Management Resources allocation and resources scheduling_Construction Management
Resources allocation and resources scheduling_Construction Management
 
Sendai framework for_disaster_risk_reduction_2015-2030
Sendai framework for_disaster_risk_reduction_2015-2030Sendai framework for_disaster_risk_reduction_2015-2030
Sendai framework for_disaster_risk_reduction_2015-2030
 
Understanding and Measuring Urban Resilience: A new UN-Habitat's initiative
Understanding and Measuring Urban Resilience: A new UN-Habitat's initiativeUnderstanding and Measuring Urban Resilience: A new UN-Habitat's initiative
Understanding and Measuring Urban Resilience: A new UN-Habitat's initiative
 
Quality control in construction
Quality control in construction Quality control in construction
Quality control in construction
 
Risk Management in Construction Project
Risk Management in Construction ProjectRisk Management in Construction Project
Risk Management in Construction Project
 
Disaster and People With Disabilities
Disaster and People With DisabilitiesDisaster and People With Disabilities
Disaster and People With Disabilities
 
Introduction to sustainability
Introduction to sustainabilityIntroduction to sustainability
Introduction to sustainability
 
Terminologies
TerminologiesTerminologies
Terminologies
 
Quality control IN CONSTRUCTION
Quality control IN CONSTRUCTIONQuality control IN CONSTRUCTION
Quality control IN CONSTRUCTION
 
Economics in Civil Engineering (Or any field of Engineering).
Economics in Civil Engineering (Or any field of Engineering).Economics in Civil Engineering (Or any field of Engineering).
Economics in Civil Engineering (Or any field of Engineering).
 
Disaster preparedness and hazard reduction processes
Disaster preparedness and hazard reduction processesDisaster preparedness and hazard reduction processes
Disaster preparedness and hazard reduction processes
 
Lecture 6: Vulnerability Analysis
Lecture 6: Vulnerability AnalysisLecture 6: Vulnerability Analysis
Lecture 6: Vulnerability Analysis
 
Factors affecting Quality of construction projects in India region
Factors affecting Quality of construction projects in India regionFactors affecting Quality of construction projects in India region
Factors affecting Quality of construction projects in India region
 

Viewers also liked

Infrastructure control
Infrastructure controlInfrastructure control
Infrastructure control
sommerville-videos
 
Architectural patterns for real-time systems
Architectural patterns for real-time systemsArchitectural patterns for real-time systems
Architectural patterns for real-time systems
sommerville-videos
 
Cybersecurity 5 improving cybersecurity
Cybersecurity 5 improving cybersecurityCybersecurity 5 improving cybersecurity
Cybersecurity 5 improving cybersecurity
sommerville-videos
 
Cybersecurity 4 security is sociotechnical issue
Cybersecurity 4 security is sociotechnical issueCybersecurity 4 security is sociotechnical issue
Cybersecurity 4 security is sociotechnical issue
sommerville-videos
 
Cybersecurity 3 cybersecurity costs and causes
Cybersecurity 3 cybersecurity costs and causesCybersecurity 3 cybersecurity costs and causes
Cybersecurity 3 cybersecurity costs and causes
sommerville-videos
 
Cybersecurity 5 improving cybersecurity
Cybersecurity 5 improving cybersecurityCybersecurity 5 improving cybersecurity
Cybersecurity 5 improving cybersecurity
sommerville-videos
 
Cybersecurity 3 cybersecurity costs and causes
Cybersecurity 3 cybersecurity costs and causesCybersecurity 3 cybersecurity costs and causes
Cybersecurity 3 cybersecurity costs and causes
sommerville-videos
 
Maroochy water breach
Maroochy water breachMaroochy water breach
Maroochy water breach
sommerville-videos
 
Introduction to systems of systems
Introduction to systems of systemsIntroduction to systems of systems
Introduction to systems of systems
sommerville-videos
 
Critical national infrastructure
Critical national infrastructureCritical national infrastructure
Critical national infrastructure
sommerville-videos
 
Cybersecurity 4 security is sociotechnical issue
Cybersecurity 4 security is sociotechnical issueCybersecurity 4 security is sociotechnical issue
Cybersecurity 4 security is sociotechnical issue
sommerville-videos
 
Cybersecurity 1 intro to cybersecurity
Cybersecurity 1 intro to cybersecurityCybersecurity 1 intro to cybersecurity
Cybersecurity 1 intro to cybersecurity
sommerville-videos
 
System safety
System safetySystem safety
System safety
sommerville-videos
 
User-Generated Content on Social Media
User-Generated Content on Social MediaUser-Generated Content on Social Media
User-Generated Content on Social Media
Meena Nagarajan
 
A Semantics-based Approach to Machine Perception
A Semantics-based Approach to Machine PerceptionA Semantics-based Approach to Machine Perception
A Semantics-based Approach to Machine Perception
Artificial Intelligence Institute at UofSC
 
Automatic Emotion Identification from Text
Automatic Emotion Identification from TextAutomatic Emotion Identification from Text
Automatic Emotion Identification from Text
Artificial Intelligence Institute at UofSC
 
Personalized and Adaptive Semantic Information Filtering for Social Media - P...
Personalized and Adaptive Semantic Information Filtering for Social Media - P...Personalized and Adaptive Semantic Information Filtering for Social Media - P...
Personalized and Adaptive Semantic Information Filtering for Social Media - P...
Artificial Intelligence Institute at UofSC
 

Viewers also liked (20)

Infrastructure control
Infrastructure controlInfrastructure control
Infrastructure control
 
Architectural patterns for real-time systems
Architectural patterns for real-time systemsArchitectural patterns for real-time systems
Architectural patterns for real-time systems
 
Cybersecurity 5 improving cybersecurity
Cybersecurity 5 improving cybersecurityCybersecurity 5 improving cybersecurity
Cybersecurity 5 improving cybersecurity
 
Cybersecurity 4 security is sociotechnical issue
Cybersecurity 4 security is sociotechnical issueCybersecurity 4 security is sociotechnical issue
Cybersecurity 4 security is sociotechnical issue
 
Cybersecurity 3 cybersecurity costs and causes
Cybersecurity 3 cybersecurity costs and causesCybersecurity 3 cybersecurity costs and causes
Cybersecurity 3 cybersecurity costs and causes
 
Cybersecurity 5 improving cybersecurity
Cybersecurity 5 improving cybersecurityCybersecurity 5 improving cybersecurity
Cybersecurity 5 improving cybersecurity
 
Cybersecurity 3 cybersecurity costs and causes
Cybersecurity 3 cybersecurity costs and causesCybersecurity 3 cybersecurity costs and causes
Cybersecurity 3 cybersecurity costs and causes
 
Infrastructure dependability
Infrastructure dependabilityInfrastructure dependability
Infrastructure dependability
 
Maroochy water breach
Maroochy water breachMaroochy water breach
Maroochy water breach
 
Introduction to systems of systems
Introduction to systems of systemsIntroduction to systems of systems
Introduction to systems of systems
 
Critical national infrastructure
Critical national infrastructureCritical national infrastructure
Critical national infrastructure
 
Cybersecurity 4 security is sociotechnical issue
Cybersecurity 4 security is sociotechnical issueCybersecurity 4 security is sociotechnical issue
Cybersecurity 4 security is sociotechnical issue
 
Cybersecurity 1 intro to cybersecurity
Cybersecurity 1 intro to cybersecurityCybersecurity 1 intro to cybersecurity
Cybersecurity 1 intro to cybersecurity
 
System safety
System safetySystem safety
System safety
 
System success and failure
System success and failureSystem success and failure
System success and failure
 
User-Generated Content on Social Media
User-Generated Content on Social MediaUser-Generated Content on Social Media
User-Generated Content on Social Media
 
A Semantics-based Approach to Machine Perception
A Semantics-based Approach to Machine PerceptionA Semantics-based Approach to Machine Perception
A Semantics-based Approach to Machine Perception
 
Satya Sahoo Thesis Defense
Satya Sahoo Thesis DefenseSatya Sahoo Thesis Defense
Satya Sahoo Thesis Defense
 
Automatic Emotion Identification from Text
Automatic Emotion Identification from TextAutomatic Emotion Identification from Text
Automatic Emotion Identification from Text
 
Personalized and Adaptive Semantic Information Filtering for Social Media - P...
Personalized and Adaptive Semantic Information Filtering for Social Media - P...Personalized and Adaptive Semantic Information Filtering for Social Media - P...
Personalized and Adaptive Semantic Information Filtering for Social Media - P...
 

Similar to Infrastructure resilience

Ch14 - Resilience Engineering
Ch14 - Resilience EngineeringCh14 - Resilience Engineering
Ch14 - Resilience Engineering
Harsh Verdhan Raj
 
Ch14 resilience engineering
Ch14 resilience engineeringCh14 resilience engineering
Ch14 resilience engineering
software-engineering-book
 
Network Security for Computer science and Engineering.ppt
Network Security for Computer science and Engineering.pptNetwork Security for Computer science and Engineering.ppt
Network Security for Computer science and Engineering.ppt
AkfeteAssefa
 
Preparing for a Black Swan: Planning and Programming for Risk Mitigation in E...
Preparing for a Black Swan: Planning and Programming for Risk Mitigation in E...Preparing for a Black Swan: Planning and Programming for Risk Mitigation in E...
Preparing for a Black Swan: Planning and Programming for Risk Mitigation in E...
juliekannai
 
Availability and reliability
Availability and reliabilityAvailability and reliability
Availability and reliability
sommerville-videos
 
Sayon MS Thesis Presentation Draft-4
Sayon MS Thesis Presentation Draft-4Sayon MS Thesis Presentation Draft-4
Sayon MS Thesis Presentation Draft-4Sayonsom Chanda
 
Resilience of Critical Infrastructures to Climate Change
Resilience of Critical Infrastructures to Climate ChangeResilience of Critical Infrastructures to Climate Change
Resilience of Critical Infrastructures to Climate Change
eu-circle
 
Resilience of Critical Infrastructures to Climate Change (old)
Resilience of Critical Infrastructures to Climate Change (old)Resilience of Critical Infrastructures to Climate Change (old)
Resilience of Critical Infrastructures to Climate Change (old)
eu-circle
 
Information Security Concepts.pdf
Information Security Concepts.pdfInformation Security Concepts.pdf
Information Security Concepts.pdf
SameeraSarathchandra1
 
FAILURE FREE CLOUD COMPUTING ARCHITECTURES
FAILURE FREE CLOUD COMPUTING ARCHITECTURESFAILURE FREE CLOUD COMPUTING ARCHITECTURES
FAILURE FREE CLOUD COMPUTING ARCHITECTURES
ijcsit
 
Failure Free Cloud Computing Architectures
Failure Free Cloud Computing ArchitecturesFailure Free Cloud Computing Architectures
Failure Free Cloud Computing Architectures
AIRCC Publishing Corporation
 
Power_Grid_Resilence.pptx
Power_Grid_Resilence.pptxPower_Grid_Resilence.pptx
Power_Grid_Resilence.pptx
DrDillipKumarMishra
 
Past and future of integrity based attacks in ics environments
Past and future of integrity based attacks in ics environmentsPast and future of integrity based attacks in ics environments
Past and future of integrity based attacks in ics environments
Joe Slowik
 
Resilience Shift - overview of our programme
Resilience Shift - overview of our programmeResilience Shift - overview of our programme
Resilience Shift - overview of our programme
The Resilience Shift
 
An Investigation of Fault Tolerance Techniques in Cloud Computing
An Investigation of Fault Tolerance Techniques in Cloud ComputingAn Investigation of Fault Tolerance Techniques in Cloud Computing
An Investigation of Fault Tolerance Techniques in Cloud Computing
ijtsrd
 
Cybersecurity 1. intro to cybersecurity
Cybersecurity 1. intro to cybersecurityCybersecurity 1. intro to cybersecurity
Cybersecurity 1. intro to cybersecurity
sommerville-videos
 
SMART Seminar Series: "Infrastructure Resilience: Planning for Future Extreme...
SMART Seminar Series: "Infrastructure Resilience: Planning for Future Extreme...SMART Seminar Series: "Infrastructure Resilience: Planning for Future Extreme...
SMART Seminar Series: "Infrastructure Resilience: Planning for Future Extreme...
SMART Infrastructure Facility
 
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical InfrastructureVarsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
itnewsafrica
 
Cybersecurity Critical Infrastructure Threats and Examples 2022- Presentation...
Cybersecurity Critical Infrastructure Threats and Examples 2022- Presentation...Cybersecurity Critical Infrastructure Threats and Examples 2022- Presentation...
Cybersecurity Critical Infrastructure Threats and Examples 2022- Presentation...
Certrec
 
Best Practices for Network Security Management
Best Practices for Network Security Management Best Practices for Network Security Management
Best Practices for Network Security Management
Skybox Security
 

Similar to Infrastructure resilience (20)

Ch14 - Resilience Engineering
Ch14 - Resilience EngineeringCh14 - Resilience Engineering
Ch14 - Resilience Engineering
 
Ch14 resilience engineering
Ch14 resilience engineeringCh14 resilience engineering
Ch14 resilience engineering
 
Network Security for Computer science and Engineering.ppt
Network Security for Computer science and Engineering.pptNetwork Security for Computer science and Engineering.ppt
Network Security for Computer science and Engineering.ppt
 
Preparing for a Black Swan: Planning and Programming for Risk Mitigation in E...
Preparing for a Black Swan: Planning and Programming for Risk Mitigation in E...Preparing for a Black Swan: Planning and Programming for Risk Mitigation in E...
Preparing for a Black Swan: Planning and Programming for Risk Mitigation in E...
 
Availability and reliability
Availability and reliabilityAvailability and reliability
Availability and reliability
 
Sayon MS Thesis Presentation Draft-4
Sayon MS Thesis Presentation Draft-4Sayon MS Thesis Presentation Draft-4
Sayon MS Thesis Presentation Draft-4
 
Resilience of Critical Infrastructures to Climate Change
Resilience of Critical Infrastructures to Climate ChangeResilience of Critical Infrastructures to Climate Change
Resilience of Critical Infrastructures to Climate Change
 
Resilience of Critical Infrastructures to Climate Change (old)
Resilience of Critical Infrastructures to Climate Change (old)Resilience of Critical Infrastructures to Climate Change (old)
Resilience of Critical Infrastructures to Climate Change (old)
 
Information Security Concepts.pdf
Information Security Concepts.pdfInformation Security Concepts.pdf
Information Security Concepts.pdf
 
FAILURE FREE CLOUD COMPUTING ARCHITECTURES
FAILURE FREE CLOUD COMPUTING ARCHITECTURESFAILURE FREE CLOUD COMPUTING ARCHITECTURES
FAILURE FREE CLOUD COMPUTING ARCHITECTURES
 
Failure Free Cloud Computing Architectures
Failure Free Cloud Computing ArchitecturesFailure Free Cloud Computing Architectures
Failure Free Cloud Computing Architectures
 
Power_Grid_Resilence.pptx
Power_Grid_Resilence.pptxPower_Grid_Resilence.pptx
Power_Grid_Resilence.pptx
 
Past and future of integrity based attacks in ics environments
Past and future of integrity based attacks in ics environmentsPast and future of integrity based attacks in ics environments
Past and future of integrity based attacks in ics environments
 
Resilience Shift - overview of our programme
Resilience Shift - overview of our programmeResilience Shift - overview of our programme
Resilience Shift - overview of our programme
 
An Investigation of Fault Tolerance Techniques in Cloud Computing
An Investigation of Fault Tolerance Techniques in Cloud ComputingAn Investigation of Fault Tolerance Techniques in Cloud Computing
An Investigation of Fault Tolerance Techniques in Cloud Computing
 
Cybersecurity 1. intro to cybersecurity
Cybersecurity 1. intro to cybersecurityCybersecurity 1. intro to cybersecurity
Cybersecurity 1. intro to cybersecurity
 
SMART Seminar Series: "Infrastructure Resilience: Planning for Future Extreme...
SMART Seminar Series: "Infrastructure Resilience: Planning for Future Extreme...SMART Seminar Series: "Infrastructure Resilience: Planning for Future Extreme...
SMART Seminar Series: "Infrastructure Resilience: Planning for Future Extreme...
 
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical InfrastructureVarsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
 
Cybersecurity Critical Infrastructure Threats and Examples 2022- Presentation...
Cybersecurity Critical Infrastructure Threats and Examples 2022- Presentation...Cybersecurity Critical Infrastructure Threats and Examples 2022- Presentation...
Cybersecurity Critical Infrastructure Threats and Examples 2022- Presentation...
 
Best Practices for Network Security Management
Best Practices for Network Security Management Best Practices for Network Security Management
Best Practices for Network Security Management
 

More from sommerville-videos

Introduction to real time software systems script
Introduction to real time software systems scriptIntroduction to real time software systems script
Introduction to real time software systems script
sommerville-videos
 
System of systems classification
System of systems classificationSystem of systems classification
System of systems classificationsommerville-videos
 
Reuse landscape
Reuse landscapeReuse landscape
Reuse landscape
sommerville-videos
 
Scaling agile
Scaling agileScaling agile
Scaling agile
sommerville-videos
 
Agile methods for large systems
Agile methods for large systemsAgile methods for large systems
Agile methods for large systems
sommerville-videos
 
User stories
User storiesUser stories
User stories
sommerville-videos
 
Agile and plan based development processes
Agile and plan based development processesAgile and plan based development processes
Agile and plan based development processes
sommerville-videos
 
Fundamental software engineering activities
Fundamental software engineering activitiesFundamental software engineering activities
Fundamental software engineering activities
sommerville-videos
 
Introducing Software Engineering
Introducing Software EngineeringIntroducing Software Engineering
Introducing Software Engineering
sommerville-videos
 
Why se script
Why se scriptWhy se script
Why se script
sommerville-videos
 
Ariane 5 launcher failure
Ariane 5 launcher failure Ariane 5 launcher failure
Ariane 5 launcher failure
sommerville-videos
 
Airbus Flight Control System
Airbus Flight Control SystemAirbus Flight Control System
Airbus Flight Control System
sommerville-videos
 
Stakeholders, viewpoints and concerns
Stakeholders, viewpoints and concernsStakeholders, viewpoints and concerns
Stakeholders, viewpoints and concerns
sommerville-videos
 
Requirements engineering processes
Requirements engineering processesRequirements engineering processes
Requirements engineering processes
sommerville-videos
 
Requirements engineering challenges
Requirements engineering challengesRequirements engineering challenges
Requirements engineering challenges
sommerville-videos
 
Intro to requirements eng.
Intro to requirements eng.Intro to requirements eng.
Intro to requirements eng.
sommerville-videos
 
Introducing sociotechnical systems
Introducing sociotechnical systemsIntroducing sociotechnical systems
Introducing sociotechnical systemssommerville-videos
 
Critical systems engineering
Critical systems engineeringCritical systems engineering
Critical systems engineering
sommerville-videos
 

More from sommerville-videos (20)

Introduction to real time software systems script
Introduction to real time software systems scriptIntroduction to real time software systems script
Introduction to real time software systems script
 
System of systems classification
System of systems classificationSystem of systems classification
System of systems classification
 
Reuse landscape
Reuse landscapeReuse landscape
Reuse landscape
 
Scaling agile
Scaling agileScaling agile
Scaling agile
 
Agile methods for large systems
Agile methods for large systemsAgile methods for large systems
Agile methods for large systems
 
User stories
User storiesUser stories
User stories
 
Agile and plan based development processes
Agile and plan based development processesAgile and plan based development processes
Agile and plan based development processes
 
Fundamental software engineering activities
Fundamental software engineering activitiesFundamental software engineering activities
Fundamental software engineering activities
 
Introducing Software Engineering
Introducing Software EngineeringIntroducing Software Engineering
Introducing Software Engineering
 
Why se script
Why se scriptWhy se script
Why se script
 
Ariane 5 launcher failure
Ariane 5 launcher failure Ariane 5 launcher failure
Ariane 5 launcher failure
 
Airbus Flight Control System
Airbus Flight Control SystemAirbus Flight Control System
Airbus Flight Control System
 
Warsaw airbus accident
Warsaw airbus accidentWarsaw airbus accident
Warsaw airbus accident
 
Stakeholders, viewpoints and concerns
Stakeholders, viewpoints and concernsStakeholders, viewpoints and concerns
Stakeholders, viewpoints and concerns
 
Requirements engineering processes
Requirements engineering processesRequirements engineering processes
Requirements engineering processes
 
Requirements engineering challenges
Requirements engineering challengesRequirements engineering challenges
Requirements engineering challenges
 
Intro to requirements eng.
Intro to requirements eng.Intro to requirements eng.
Intro to requirements eng.
 
Emergent properties
Emergent propertiesEmergent properties
Emergent properties
 
Introducing sociotechnical systems
Introducing sociotechnical systemsIntroducing sociotechnical systems
Introducing sociotechnical systems
 
Critical systems engineering
Critical systems engineeringCritical systems engineering
Critical systems engineering
 

Recently uploaded

GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
Guy Korland
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
ControlCase
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
Alpen-Adria-Universität
 
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to ProductionGenerative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Aggregage
 
By Design, not by Accident - Agile Venture Bolzano 2024
By Design, not by Accident - Agile Venture Bolzano 2024By Design, not by Accident - Agile Venture Bolzano 2024
By Design, not by Accident - Agile Venture Bolzano 2024
Pierluigi Pugliese
 
Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
Kari Kakkonen
 
The Metaverse and AI: how can decision-makers harness the Metaverse for their...
The Metaverse and AI: how can decision-makers harness the Metaverse for their...The Metaverse and AI: how can decision-makers harness the Metaverse for their...
The Metaverse and AI: how can decision-makers harness the Metaverse for their...
Jen Stirrup
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
Jemma Hussein Allen
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
Kari Kakkonen
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
SOFTTECHHUB
 
Introduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - CybersecurityIntroduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - Cybersecurity
mikeeftimakis1
 
PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)
Ralf Eggert
 
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdfObservability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Paige Cruz
 
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdfSAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
Peter Spielvogel
 
Assure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyesAssure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyes
ThousandEyes
 
RESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for studentsRESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for students
KAMESHS29
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
Thijs Feryn
 
Free Complete Python - A step towards Data Science
Free Complete Python - A step towards Data ScienceFree Complete Python - A step towards Data Science
Free Complete Python - A step towards Data Science
RinaMondal9
 

Recently uploaded (20)

GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
 
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to ProductionGenerative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to Production
 
By Design, not by Accident - Agile Venture Bolzano 2024
By Design, not by Accident - Agile Venture Bolzano 2024By Design, not by Accident - Agile Venture Bolzano 2024
By Design, not by Accident - Agile Venture Bolzano 2024
 
Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
 
The Metaverse and AI: how can decision-makers harness the Metaverse for their...
The Metaverse and AI: how can decision-makers harness the Metaverse for their...The Metaverse and AI: how can decision-makers harness the Metaverse for their...
The Metaverse and AI: how can decision-makers harness the Metaverse for their...
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
 
Introduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - CybersecurityIntroduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - Cybersecurity
 
PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)
 
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdfObservability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
 
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdfSAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
 
Assure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyesAssure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyes
 
RESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for studentsRESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for students
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
Free Complete Python - A step towards Data Science
Free Complete Python - A step towards Data ScienceFree Complete Python - A step towards Data Science
Free Complete Python - A step towards Data Science
 

Infrastructure resilience

  • 1. <Infrastructure resilience, 2013 Slide 1 Infrastructure resilience Ian Sommerville
  • 2. <Infrastructure resilience, 2013 Slide 2 Resilience • Resilience is the ability of assets, networks and systems to anticipate, absorb, adapt to, and recover from a disruptive event or series of events. • Resilience is about maintaining the continuity of a service in the presence of disruptive events
  • 4. <Infrastructure resilience, 2013 Slide 4 Pandemic disease • Pandemic disease is the highest impact risk because it potentially affects the whole of a national infrastructure as people become ill
  • 5. <Infrastructure resilience, 2013 Slide 5 Cyber attacks • Cyber attacks that compromise confidentiality are not likely to have a major impact on the availability of a national infrastructure • But cyber attacks that affect the control systems are more serious
  • 6. <Infrastructure resilience, 2013 Slide 6 Risk impact • Risk impact is related to the extent of the damage to infrastructure assets
  • 7. <Infrastructure resilience, 2013 Slide 7 Impact depends on locality • Local incidents, such as a terrorist attack on physical infrastructure, have limited impact because they only affect a small part of that infrastructure
  • 8. <Infrastructure resilience, 2013 Slide 8 Organisational infrastructure • Organisations may be more vulnerable than physical infrastructure • Incidents that affect the organisational infrastructure can have more significant impact – Organisations are less likely to be distributed
  • 9. <Infrastructure resilience, 2013 Slide 9 Risk impact • Because physical infrastructure is distributed, failures in one part of a physical network are localised – A crack is discovered in one bridge but this does not affect other bridges in the network
  • 10. <Infrastructure resilience, 2013 Slide 10 Software vulnerability • However, software control changes this – If common elements of an infrastructure are networked and controlled by the same software, a failure in one element (especially a malicious attack) can propagate throughout the network – Large-scale failures and unavailability therefore become possible
  • 11. <Infrastructure resilience, 2013 Slide 11 Infrastructure dependencies • All infrastructure elements now depend on power and communications • Failure and unavailable of these infrastructures has the most impact Photo: creative commons/flickr/anemoneprojectors
  • 12. <Infrastructure resilience, 2013 Slide 12 Infrastructure vulnerabilities • Limited physical protectio n
  • 13. <Infrastructure resilience, 2013 Slide 13 Infrastructure vulnerabilities • Old/insecure software control systems Image: http://commons.wikimedia.org/wiki/File:SCADA_PUMPING_STATION_1.jpg
  • 14. <Infrastructure resilience, 2013 Slide 14 Infrastructure vulnerabilities • Lack of monitoring systems • Lack of coordination across infrastructure elements
  • 15. <Infrastructure resilience, 2013 Slide 15 Infrastructure vulnerabilities • Lack of knowledge of infrastructure state or dependencies • Lack of knowledge of infrastructure demand
  • 16. <Infrastructure resilience, 2013 Slide 16 Achieving resilience
  • 17. <Infrastructure resilience, 2013 Slide 17 Resistance Provide protection against anticipated events or attacks – Flood defences – Cybersecurity awareness© Adrian Pingstone 2005
  • 18. <Infrastructure resilience, 2013 Slide 18 Resistance • Based on previous experience and assumptions • Changing world or external circumstances may mean that assumptions are invalid
  • 19. <Infrastructure resilience, 2013 Slide 19 Reliability • Infrastructure components should be designed to operate under a range of (anticipated) conditions not just ‘normal’ operating conditions
  • 20. <Infrastructure resilience, 2013 Slide 20 Reliability • Components, as far as possible, should be designed for ‘soft’, incremental rather than catastrophic failure
  • 21. <Infrastructure resilience, 2013 Slide 21 Digital and analog systems • Digital systems are more brittle than analog systems • Analog systems often fail gradually; computer-based systems often simply crash
  • 22. <Infrastructure resilience, 2013 Slide 22 Redundancy • The network or system as a whole should be designed so that there are backup installations and spare capacity available.
  • 23. <Infrastructure resilience, 2013 Slide 23 Redundancy • Examples – Computing support should be provided by different providers in different locations – Diverse generation capacity for electricity – Multiple locations for command and control
  • 24. <Infrastructure resilience, 2013 Slide 24 Response and recovery • Respond to distruptive events quickly, limiting the damage as far as possible and ensuring public safety
  • 25. <Infrastructure resilience, 2013 Slide 25 Response and recovery • Plan how to restore services as quickly as possible in the event of a loss of capability • Business continuity planning • Disaster recovery
  • 26. <Infrastructure resilience, 2013 Slide 26 Achieving resilience • Advance planning to draw up contingency plans to cover anticipated problems • (a) good design of the network and systems to ensure it has the necessary resistance, reliability and redundancy (spare capacity), and • (b) by establishing good organisational resilience to provide the ability, capacity and capability to respond and recover from disruptive events.
  • 27. <Infrastructure resilience, 2013 Slide 27 Key points • Critical infrastructure resilience is the ability of the infrastructure to continue to deliver essential services during and after a hazardous event • Infrastructure resilience depends on planning for contingencies and effective infrastructure design
  • 28. <Infrastructure resilience, 2013 Slide 28 Key points • Software control of infrastructure systems potentially increases vulnerability because the effects of an event may not be localised • Resilient infrastructure design is based on 4 R’s – resistance, reliability, redundancy, and recovery

Editor's Notes

  1. Maybe I need a slide on each of these.