Schabacker Daniel S, Levy Leslie-Anne, Evans Nate J, Fowler Jennifer M, Dickey Ellen A
Argonne National Laboratory (DOE), Strategic Security Sciences Division, Lemont, IL, United States.
Argonne National Laboratory (DOE), Decision and Infrastructure Sciences Division, Lemont, IL, United States.
Front Bioeng Biotechnol. 2019 Mar 29;7:61. doi: 10.3389/fbioe.2019.00061. eCollection 2019.
The convergence of advances in biotechnology with laboratory automation, access to data, and computational biology has democratized biotechnology and accelerated the development of new therapeutics. However, increased access to biotechnology in the digital age has also introduced additional security concerns and ultimately, spawned the new discipline of cyberbiosecurity, which encompasses cybersecurity, cyber-physical security, and biosecurity considerations. With the emergence of this new discipline comes the need for a logical, repeatable, and shared approach for evaluating facility and system vulnerabilities to cyberbiosecurity threats. In this paper, we outline the foundation of an assessment framework for cyberbiosecurity, accounting for both security and resilience factors in the physical and cyber domains. This is a unique problem set, but despite the complexity of the cyberbiosecurity field in terms of operations and governance, previous experience developing and implementing physical and cyber assessments applicable to a wide spectrum of critical infrastructure sectors provides a validated point of departure for a cyberbiosecurity assessment framework. This approach proposes to integrate existing capabilities and proven methodologies from the infrastructure assessment realm (e.g., decision science, physical security, infrastructure resilience, cybersecurity) with new expertise and requirements in the cyberbiosecurity space (e.g., biotechnology, biomanufacturing, genomics) in order to forge a flexible and defensible approach to identifying and mitigating vulnerabilities. Determining where vulnerabilities reside within cyberbiosecurity business processes can help public and private sector partners create an assessment framework to identify mitigation options for consideration that are both economically and practically viable and ultimately, allow them to manage risk more effectively.
生物技术的进步与实验室自动化、数据获取以及计算生物学的融合,使生物技术得以普及,并加速了新疗法的开发。然而,数字时代生物技术的更广泛应用也带来了更多安全问题,最终催生了网络生物安全这一新学科,它涵盖了网络安全、网络物理安全和生物安全等方面的考量。随着这一新学科的出现,需要一种逻辑清晰、可重复且共享的方法来评估设施和系统对网络生物安全威胁的脆弱性。在本文中,我们概述了网络生物安全评估框架的基础,兼顾了物理和网络领域的安全与恢复力因素。这是一个独特的问题集,尽管网络生物安全领域在运营和治理方面很复杂,但以往在开发和实施适用于广泛关键基础设施部门的物理和网络评估方面的经验,为网络生物安全评估框架提供了一个经过验证的出发点。这种方法建议将基础设施评估领域(如决策科学、物理安全、基础设施恢复力、网络安全)现有的能力和经过验证的方法与网络生物安全领域的新专业知识和要求(如生物技术、生物制造、基因组学)相结合,以形成一种灵活且可靠的方法来识别和减轻脆弱性。确定网络生物安全业务流程中的脆弱性所在位置,有助于公共和私营部门合作伙伴创建一个评估框架,以确定在经济和实际操作上都可行的缓解选项供其考虑,最终使他们能够更有效地管理风险。