{"id":{"repo_id":"nps","oai_identifier":"oai:calhoun.nps.edu:10945/66140"},"canonical_url":"https://search.dev.ndltd.org/etd/nps/oai:calhoun.nps.edu:10945/66140","repository":{"repo_id":"nps","name":"Naval Postgraduate School","base_url":"https://calhoun.nps.edu/server/oai/request"},"display":{"title":"EFFECTIVENESS OF NATIONAL CYBER POLICY TO STRENGTHEN THE SECURITY AND RESILIENCE OF CRITICAL INFRASTRUCTURE AGAINST CYBER ATTACKS","abstract":"Presidential Policy Directive (PPD) 21, Critical Infrastructure Security and Resilience, directs a whole-of-government approach to strengthening the security and resilience of critical infrastructure against physical and cyber threats. Per policy, critical infrastructure is categorized into 16 sectors. Security and resiliency efforts against cyber threats are constrained by this sector-based approach. This thesis assesses the sector-based approach by the following criteria: expertise or a notable advantage of the sector-specific agency; promotion of cybersecurity measures by the critical infrastructure community partnership structure; and legislation, policy, or sector-specific characteristics that enhance security and resilience of the sector. These assessments gauged the adequacy of organizational structures that lead and support critical infrastructure cybersecurity. Exemplar cyber attacks against critical infrastructure and response actions are described in order to demonstrate strengths and limitations of the sector-based approach. This examination reveals that the U.S. approach to critical infrastructure is well conceived and executed in general. A number of significant vulnerabilities do remain in some sectors, however, as a result of incomplete or insufficient implementation.","abstract_html":"Presidential Policy Directive (PPD) 21, Critical Infrastructure Security and Resilience, directs a whole-of-government approach to strengthening the security and resilience of critical infrastructure against physical and cyber threats. Per policy, critical infrastructure is categorized into 16 sectors. Security and resiliency efforts against cyber threats are constrained by this sector-based approach. This thesis assesses the sector-based approach by the following criteria: expertise or a notable advantage of the sector-specific agency; promotion of cybersecurity measures by the critical infrastructure community partnership structure; and legislation, policy, or sector-specific characteristics that enhance security and resilience of the sector. These assessments gauged the adequacy of organizational structures that lead and support critical infrastructure cybersecurity. Exemplar cyber attacks against critical infrastructure and response actions are described in order to demonstrate strengths and limitations of the sector-based approach. This examination reveals that the U.S. approach to critical infrastructure is well conceived and executed in general. A number of significant vulnerabilities do remain in some sectors, however, as a result of incomplete or insufficient implementation.","abstract_has_math":false,"creators":["Simon, Ian G."],"institution":"Monterey, CA; Naval Postgraduate School","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":"Information Sciences (IS)","school":null,"contributors":[],"advisors":["Davis, Duane T."],"committee_chairs":[],"committee_members":[],"year":2020,"date_issued":"2020-09","date_published":"2020-09","updated_at":"2026-07-27T20:26:05Z","subjects":[],"languages":[],"rights":["This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10945/66140","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Davis, Duane T."]},{"key":"dc:contributor.department","label":"Department","values":["Information Sciences (IS)"]},{"key":"dc:creator","label":"Author","values":["Simon, Ian G."]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["Sep-20"]},{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2020-11-18T00:23:22Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2020-11-18T00:23:22Z"]},{"key":"dc:date.issued","label":"Date","values":["2020-09"]},{"key":"dc:publisher","label":"Institution","values":["Monterey, CA; Naval Postgraduate School"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10945/66140"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Presidential Policy Directive (PPD) 21, Critical Infrastructure Security and Resilience, directs a whole-of-government approach to strengthening the security and resilience of critical infrastructure against physical and cyber threats. Per policy, critical infrastructure is categorized into 16 sectors. Security and resiliency efforts against cyber threats are constrained by this sector-based approach. This thesis assesses the sector-based approach by the following criteria: expertise or a notable advantage of the sector-specific agency; promotion of cybersecurity measures by the critical infrastructure community partnership structure; and legislation, policy, or sector-specific characteristics that enhance security and resilience of the sector. These assessments gauged the adequacy of organizational structures that lead and support critical infrastructure cybersecurity. Exemplar cyber attacks against critical infrastructure and response actions are described in order to demonstrate strengths and limitations of the sector-based approach. This examination reveals that the U.S. approach to critical infrastructure is well conceived and executed in general. A number of significant vulnerabilities do remain in some sectors, however, as a result of incomplete or insufficient implementation."]},{"key":"dc:title","label":"Title","values":["EFFECTIVENESS OF NATIONAL CYBER POLICY TO STRENGTHEN THE SECURITY AND RESILIENCE OF CRITICAL INFRASTRUCTURE AGAINST CYBER ATTACKS"]}]}],"canonical_facts":{"dc:contributor.advisor":["Davis, Duane T."],"dc:contributor.department":["Information Sciences (IS)"],"dc:creator":["Simon, Ian G."],"dc:date":["Sep-20"],"dc:date.accessioned":["2020-11-18T00:23:22Z"],"dc:date.available":["2020-11-18T00:23:22Z"],"dc:date.issued":["2020-09"],"dc:description.abstract":["Presidential Policy Directive (PPD) 21, Critical Infrastructure Security and Resilience, directs a whole-of-government approach to strengthening the security and resilience of critical infrastructure against physical and cyber threats. Per policy, critical infrastructure is categorized into 16 sectors. Security and resiliency efforts against cyber threats are constrained by this sector-based approach. This thesis assesses the sector-based approach by the following criteria: expertise or a notable advantage of the sector-specific agency; promotion of cybersecurity measures by the critical infrastructure community partnership structure; and legislation, policy, or sector-specific characteristics that enhance security and resilience of the sector. These assessments gauged the adequacy of organizational structures that lead and support critical infrastructure cybersecurity. Exemplar cyber attacks against critical infrastructure and response actions are described in order to demonstrate strengths and limitations of the sector-based approach. This examination reveals that the U.S. approach to critical infrastructure is well conceived and executed in general. A number of significant vulnerabilities do remain in some sectors, however, as a result of incomplete or insufficient implementation."],"dc:identifier.uri":["https://hdl.handle.net/10945/66140"],"dc:publisher":["Monterey, CA; Naval Postgraduate School"],"dc:rights":["This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States"],"dc:title":["EFFECTIVENESS OF NATIONAL CYBER POLICY TO STRENGTHEN THE SECURITY AND RESILIENCE OF CRITICAL INFRASTRUCTURE AGAINST CYBER ATTACKS"],"dc:type":["Thesis"]},"updated_at":"2026-07-27T20:26:05Z"}