InfoGram

This page may contain links to non-U.S. government websites. What this means to you »

InfoGram November 21, 2002

NOTE: This InfoGram will be distributed weekly to provide members of the emergency services sector with news and information concerning the protection of their critical infrastructures. For further information please contact the U.S. Fire Administration's Critical Infrastructure Protection Information Center at (301) 447-1325 or email at usfacipc@dhs.gov.

8 Major Tenets of CIP

With each passing day, there seems to be increasing attention given to the protection of critical infrastructures by federal, state, and local officials, including those of the emergency first response services. The CIPIC is a witness to this progression given the constantly growing number of daily phone calls and electronic messages. Therefore, for the benefit of those who may be new to the discipline of critical infrastructure protection (CIP), the eight majors tenets of CIP are presented as follows:

  1. Terrorist attacks, natural disasters, and HazMat accidents can weaken an organization's performance or prevent its operations.
  2. Among all the processes and procedures involved in emergency preparedness, CIP is possibly the most important component.
  3. CIP protects the people, physical entities, and cyber systems that are indispensably necessary for survivability, continuity of operations, and mission success.
  4. It is not just about security; CIP is mainly about operational effectiveness and "response-ability."
  5. CIP involves the application of a five-step systematic, analytical process:
    • Identify critical infrastructures
    • Determine the threats
    • Analyze vulnerabilities
    • Assess risks
    • Apply countermeasures
  6. There will never be enough resources to achieve total emergency preparedness including infrastructure protection.
  7. CIP requires that senior leaders make tough decisions about what assets really need
    protection by the application of scarce resources.
  8. There should be no tolerance for waste and misguided spending in the business of emergency preparedness and CIP.

Aggressive Behavior

The added anxieties or tensions brought upon emergency first responders in the past fourteen months raise the possibility for aggressive behavior by firefighters and emergency medical personnel. Sporadic incidents provide some indication that concerns about preparedness for terrorist attacks involving weapons of mass destruction, personal safety, family security, etc., have created more than normal amounts of negative stress for first responders. It is human nature that this stress will occasionally manifest itself in aggressive behavior. The CIPIC recommends that emergency service department leaders consider the potential for this stress to be disruptive and, additionally, degrade the protection of the organization's critical infrastructures.

Much has been written about defusing aggressive behavior. Since violent action can have multiple adverse effects, psychologists agree that it must be addressed within any organization. For those chief officers who may be confronted with such workplace behavior, the following fifteen fundamentals are listed as a reminder for future use with a probable or confirmed aggressive employee:

Dealing with the Warning Overdose

Among all the challenges that chief officers contend with on a daily basis, another concern could become problematic if it has not already done so: dealing with the overdose of threat advisories and warnings. If they have not already appeared, the potential still exists that leaders and personnel of the emergency services will experience the symptoms of "alert fatigue." This malaise, cynicism, or despair, according to terrorism analysts in the United States and United Kingdom, may be triggered by the many threat advisories and warnings that are issued without an incident or a confirmed attempt at one. These specialists expressed fear that people—including the first line soldiers of homeland security—will stop paying attention, which is exactly what the terrorists want.

Recognizing the patient tactics of committed terrorists, the CIPIC also encourages all firefighters and emergency medical personnel to support each other while maintaining an uninterrupted, elevated state of awareness for suspicious or unusual activities. But for all personnel to effectively remain alert will necessitate that chief officers and their staff comprehend the physiological and psychological effects of "alert fatigue" among other ill effects of stress. This understanding is essential to taking care of subordinates. After all, protecting this exceedingly invaluable critical infrastructure—personnel—is a fundamental leadership premise of the fire-rescue service.

Cyberattacks Imminent?

The CIPIC recommends that all emergency response departments review their protective measures for organizational cyber systems, especially if those systems in anyway connect to the Internet. This recommendation is made because security experts and two former CIA officials recently said that "warnings of cyberattacks by al Qaeda against western infrastructures should not be taken lightly."

The former CIA chief of counterterrorism explained that a number of extremists, some of them close to al Qaeda, have developed expertise in computer science. "And some are well schooled in how to carry out cyberattacks," according to materials retrieved from al Qaeda camps in Afghanistan.

Additionally, in an exclusive interview with Computerworld early this week, Sheikh Omar Bakri Muhammad, a London-based fundamentalist Islamic cleric with known ties to Osama bin Laden, said al Qaeda and other extremist Muslim groups around the world are actively planning to use the Internet as a weapon in their "defensive" jihad against the United States.

Disclaimer of Endorsement

The U.S. Fire Administration/EMR-ISAC does not endorse the organizations sponsoring linked websites, and does not endorse the views they express or the products/services they offer.

Fair Use Notice

This INFOGRAM may contain copyrighted material that was not specifically authorized by the copyright owner. EMR-ISAC personnel believe this constitutes "fair use" of copyrighted material as provided for in section 107 of the U.S. Copyright Law. If you wish to use copyrighted material contained within this document for your own purposes that go beyond "fair use," you must obtain permission from the copyright owner.

Reporting Notice

DHS and the FBI encourage recipients of this document to report information concerning suspicious or criminal activity to DHS and/or the FBI. The DHS National Operation Center (NOC) can be reached by telephone at 202-282-9685 or by email at NOC.Fusion@dhs.gov.

The FBI regional phone numbers can be found online at www.fbi.gov/contact/fo/fo.htm

For information affecting the private sector and critical infrastructure, contact the National Infrastructure Coordinating Center (NICC), a sub-element of the NOC. The NICC can be reached by telephone at 202-282-9201 or by email at NICC@dhs.gov.

When available, each report submitted should include the date, time, location, type of activity, number of people and type of equipment used for the activity, the name of the submitting company or organization, and a designated point of contact.

RSS FeedWeekly INFOGRAM's are now available as an RSS Feed. More Information »