Download presentation
Presentation is loading. Please wait.
Published bySheena Hudson Modified over 5 years ago
1
Concepts & Thoughts on Operational Resiliency (Feb 11)
Dave Lush, SME Aha! Analytics Presented at the Financial Systems Technology Consortium (FSTC) Summit in NYC June 08
2
Contents Purpose Background Key Concepts and Operational Architecture
A Proposed Approach Summary/Conclusions Questions/Discussion Back Up Slides
3
operational resiliency
Purpose To communicate some ideas/concepts regarding operational resiliency and various facets I want to provide an overview of NASIC’s approach to intelligence knowledge Mgt and virtual/digital production. In so doing I want to tell a story which traces the approach, concepts and architecture that I will describe back to very strong requirements and mission imperatives. Suffice to say here that the requirements mandate that we attack the digital production problem back up stream in the intelligence process and at the product neutral intelligence knowledge level. So, in this connection I’ll start with some background info and then state the high level system requirements that must be satisfied in order to achieve its mission. These are crucial to the argument and NASIC’s behavior in this context. Then I want to discuss some core concepts (to include the ontology driven analysis and production paradigm) that are at the heart of NASIC’s approach and which we believe make our approach very extensible and powerful. Then with the background covered, requirements strongly stated, and conceptual preliminaries out of the way, I will state our vision/objectives and then follow with an overview of the system and technical architecture which is emerging in order to realize the vision, objectives, requirements stated. Then I provide overview of our SAVANT program and provide operational or near operational examples. Finally the summary and call for questions/discussion.
4
Quick Background Advances in and Dependencies on Technology
Growth in Complexity of Operations/Systems Increasing Threat - Particularly in the Cyber Domain Security and Continuity of Ops Challenges Imperative for Operational “Resiliency”
5
What Is Operational Resiliency?
Ops Resiliency: the capability to sustain the enterprise and continue achieving the mission in the presence & realization of risk Risk/Threat Is at the Heart of It! Risk: an uncertain condition or event that, if it occurs, has a positive or negative impact Threat: risk that has only negative impact In the Context of Ops Resiliency Risk Is Threat Several Key Ideas Relative to Risk/Threat Are Strongly Suggested i.e.: Risk Identification: Risk Analysis: Risk Mitigation: Risk Response:
6
What Must We Do? To Achieve Operational Resiliency
Have a Proper Intent, Vision, and a Top Level Plan Identify and Analyze Threats Value at Risk (VAR) Analysis Develop an Ops Resiliency CONOPS Processes, Flows, Roles Business Ops Model(s) Threat Model(s) Security Model(s) Attack Model(s) Response Model(s) Policies/Rules Courses of Action Plan/Develop Requisite Knowledge Model Driven Automation Develop a Deployment Plan Deploy the CONOPS and the Automation Accordingly Measure Performance and Improve
7
Actions for Attaining Ops Resiliency
8
Ops Resiliency Actions
9
Operational Processes/Systems
Model/Knowledge Driven Orgs/Systems CONCEPTUAL MODEL EXTERNALIZED MACHINE READABLE INFORMATION MODELS OR ONTOLOGIES The Idea Behind Knowledge Driven Organizations/Systems Is To Drive Organizational Processes and Associated Systems Via Externalized Conceptual Models and Associated Ontologies or Information Models Instantiated with Data Relevant to the Operational Situation ANALYST Incoming Observations and Data Cognitive and Ontology Development Processes CONCEPTUAL MODEL & ONTOLOGY DEVELOPMENT METHODOLOGIES AND TOOL(S) Knowledge Driven Operational Processes/Systems Figure 3: Model/Knowledge Driven Orgs/Systems
10
Execute Courses of Action
Good Guys Threat Business Ops The Threat/Attack Event Cloud Sense, Detect & Collect Process & Analyze Decide Apply Polices/Rules Execute Courses of Action (COAs) Tactical Model Driven Ops Resiliency Apparatus Ops Resiliency Knowledge Base Discover Generate Deliver Dynamic Ops Resiliency Info Ops Resiliency CONOPS, Models Associated Executables Requisite Complexity, Structure, Detail Rich Content Meta-data MLS Ready Readily Re-purposed Data, Info, Knowledge Drives Agent Activity Drives Machine-to-Machine Processes Drives Generation of JIT Dynamic Products Process & Analyze Data Develop & Update Conceptual Models & Semantics Develop Update Resliency CONOPS Develop Update Requisite Automation Ops Resiliency Learning and Control System Strategic Ops Resiliency Apparatus Accomplish Value At Risk (VAR) Analysis Biz CONOPS Info All of this occurs in the context of the Resiliency Engineering Framework (REF) and represents an application of the REF
11
Key Conclusions Ops Resiliency Is All About Risk and Risk Mitigation and Risk Response Must Have Proper Vision, Framework, and a Plan (REF) Probabilities and Impacts Must Be Analyzed Via Value at Risk (VAR) Analysis Must Develop Requisite CONOPS Which Includes Operations and Threat/Attack Models, Policies/Rules, Courses of Action (COAs) Must Capture and Manage the Knowledge Associated with the CONOPS and Models (Knowledge Management) Must Have Must Have Requisite Knowledge-driven Systems for Automation of the CONOPS Must Deploy and Execute with Discipline
12
Questions/Discussion?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.