Using Operational Risk Management (ORM) to Improve Computer Network Defense (CND) Performance in the Department of the Navy (DON)

Abstract

Operational Risk Management (ORM) has been credited with reducing the Navy's mishap rate to all time lows, especially in Naval Aviation. Through the use of a five-step process, ORM has been able to change the decision makers' paradigm of day-to-day operations in naval fleet units, making safety the paramount factor that would allow fleet commanding officers to conserve their assets, yet meet the requirement to train in high-risk environments. ORM is a process that mitigates the risk associated with the high-risk environment that naval fleet units operate in. Not unlike naval fleet units, our computer networks, operate in a high-risk environment-the Internet. Crackers are able to penetrate what were thought to be secure networks, and copy, modify, disrupt or destroy valuable information The risk posed to the Navy's computer network systems is very great. Given the Navy's adoption of 'Network-Centric Warfare' and the Navy-Marine Corps Intranet (NMCI), the hazards faced by the possible compromise of these computer network systems are as great as any a fleet unit would encounter in its normal operating environment. The objective of this thesis is to translate ORM practices into Information Assurance Risk Management (IARM) practices, and demonstrate IARM's utility in identifying, quantifying, and mitigating the security risks associated with computer networks.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Mar 01, 2001
Accession Number
ADA391071

Entities

People

  • Ernest D. Hernandez

Organizations

  • Naval Postgraduate School

Tags

Communities of Interest

  • Cyber
  • Energy and Power Technologies
  • Human Systems
  • Weapons Technologies

DTIC Thesaurus Topics

  • Air Force
  • Computer Network Security
  • Computer Networks
  • Computers
  • Cybersecurity
  • Denial Of Service Attack
  • Electronic Mail
  • Information Operations
  • Information Systems
  • Information Warfare
  • Military Organizations
  • Military Science
  • Network Protocols
  • Network Science
  • Security Protocols
  • Students
  • Warfare

Fields of Study

  • Environmental science

Readers

  • Aviation Safety Risk Assessment.
  • Cybersecurity.
  • Systems Analysis and Design