API SECURITY-2004 Security Vulnerability Assessment Methodology for the Petroleum and Petrochemical Industries (Second Edition)《石油和石化工业的安全易受攻击性评估方法.第2版》.pdf
《API SECURITY-2004 Security Vulnerability Assessment Methodology for the Petroleum and Petrochemical Industries (Second Edition)《石油和石化工业的安全易受攻击性评估方法.第2版》.pdf》由会员分享,可在线阅读,更多相关《API SECURITY-2004 Security Vulnerability Assessment Methodology for the Petroleum and Petrochemical Industries (Second Edition)《石油和石化工业的安全易受攻击性评估方法.第2版》.pdf(166页珍藏版)》请在麦多课文档分享上搜索。
1、October 2004Security Vulnerability Assessment Methodology for the Petroleum and Petrochemical Industries, Second EditionOctober 2004 Security Vulnerability Assessment Methodology for the Petroleum and Petrochemical Industries, Second Edition American Petroleum Institute 1220 L Street, NW Washington,
2、 DC 20005-4070 National Petrochemical thereby enhancing the security of our nations energy infrastructure. API and NPRA wish to express sincere appreciation to the member companies who have made personnel available to work on this document. We especially thank the Department of Homeland Security and
3、 its Directorate of Information Analysis Identify and characterize threats against those assets and evaluate the assets in terms of attractiveness of the targets to each adversary and the consequences if they are damaged or stolen; Identify potential security vulnerabilities that threaten the assets
4、 service or integrity; Determine the risk represented by these events or conditions by determining the likelihood of a successful event and the consequences of an event if it were to occur; Rank the risk of the event occurring and, if high risk, make recommendations for lowering the risk; Identify a
5、nd evaluate risk mitigation options (both net risk reduction and benefit/cost analyses) and re-assess risk to ensure adequate countermeasures are being applied. This guidance was developed for the industry as an adjunct to other available references which includes: American Petroleum Institute, “Sec
6、urity Guidelines for the Petroleum Industry”, May, 2003; API RP 70, “Security for Offshore Oil and Natural Gas Operations”, First Edition, April, 2003; 2 AMERICAN PETROLEUM INSTITUTE AND NATIONAL PETROCHEMICAL “Vulnerability Analysis Methodology for Chemical Facilities (VAM-CF)”, Sandia National Lab
7、oratories, 2002. API and NPRA would like to acknowledge the contribution of the Center for Chemical Process Safety (CCPS) compiled in their “Guidelines for Analyzing and Managing the Security of Fixed Chemical Sites.” It was this initial body of work that was used as a basis for developing the first
8、 edition of the API NPRA SVA methodology. Although similar in nature, the SVA Method was developed for the petroleum and petrochemical industry, at both fixed and mobile systems. Examples have been added that demonstrate applicability at various operating segments of the industry. Owner/Operators ma
9、y want to use any of the methods above, or another equivalent and appropriate methodology in conducting their SVAs. These guidelines should also be considered in light of any applicable federal, state and local laws and regulations. The guidance is intended for site managers, security managers, proc
10、ess safety managers, and others responsible for conducting security vulnerability analyses and managing security at petroleum and petrochemical facilities. The method described in this guidance may be widely applicable to a full spectrum of security issues, but the key hazards of concern are malevol
11、ent acts, such as terrorism, that have the potential for widespread casualties or damage. These guidelines provide additional industry segment specific guidance to the overall security plan and SVA method presented in Part I of the API Security Guidelines for the Petroleum Industry. 1.3 SECURITY VUL
12、NERABILITY ASSESSMENT AND SECURITY MANAGEMENT PRINCIPLES Owner/Operators should ensure the security of facilities and the protection of the public, the environment, workers, and the continuity of the business through the management of security risks. The premise of the guidelines is that security ri
13、sks should be managed in a risk-based, performance-oriented management process. The foundation of the security management approach is the need to identify and analyze security threats and vulnerabilities, and to evaluate the adequacy of the countermeasures provided to mitigate the threats. Security
14、Vulnerability Assessment is a management tool that can be used to assist in accomplishing this task, and to help the owner/operator in making decisions on the need for and value of enhancements. The need for security enhancements will be determined partly by factors such as the degree of the threat,
15、 the degree of vulnerability, the possible consequences of an incident, and the attractiveness of the asset to adversaries. In the case of terrorist threats, higher risk sites are those that have critical importance, are attractive targets to the adversary, have a high level of consequences, and whe
16、re the level of vulnerability and threat is high. SVAs are not necessarily a quantitative risk assessment, but are usually performed qualitatively using the best judgment of the SVA Team. The expected outcome is a qualitative determination of risk to provide a sound basis for rank ordering of the se
17、curity-related risks and thus establishing priorities for the application of countermeasures. A basic premise is that all security risks cannot be completely prevented. The security objectives are to employ four basic strategies to help minimize the risk: 1. Deter 2. Detect 3. Delay 4. Respond Appro
18、priate strategies for managing security can vary widely depending on the individual circumstances of the facility, including the type of facility and the threats facing the facility. As a result, this guideline does not prescribe security measures but instead suggests means of identifying, analyzing
19、, and reducing vulnerabilities. The specific situations must be evaluated individually by local management using best judgment of applicable practices. Appropriate security risk management decisions must be made commensurate with the risks. This flexible approach recognizes that there isnt a uniform
20、 approach to security in the petroleum industry, and that resources are best applied to mitigate high-risk situations primarily. All Owner/Operators are encouraged to seek out assistance and coordinate efforts with federal, state, and local law enforcement agencies, and with the local emergency serv
21、ices and Local Emergency Planning Committee. Owner/Operators can also obtain and share intelligence, coordinate training, and tap other resources to help deter attacks and to manage emergencies. SECURITY VULNERABILITY ASSESSMENT METHODOLOGY FOR THE PETROLEUM AND PETROCHEMICAL INDUSTRIES 3 Chapter 2
22、Security Vulnerability Assessment Concepts 2.1 INTRODUCTION TO SVA TERMS A Security Vulnerability Assessment (SVA) is the process that includes determining the likelihood of an adversary successfully exploiting vulnerability and estimating the resulting degree of damage or impact. Based on this asse
23、ssment, judgments can be made on degree of risk and the need for additional countermeasures. To conduct a SVA, key terms and concepts must be understood as explained in this chapter. 2.2 RISK DEFINITION FOR SVA For the purposes of a SVA, the definition of risk is shown in Figure 2.1. The risk that i
24、s being analyzed for the SVA is defined as an expression of the likelihood that a defined threat will target and successfully attack a specific security vulnerability of a particular target or combination of targets to cause a given set of consequences. The complete SVA may evaluate one or more issu
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- APISECURITY2004SECURITYVULNERABILITYASSESSMENTMETHODOLOGYFORTHEPETROLEUMANDPETROCHEMICALINDUSTRIESSECONDEDITION

链接地址:http://www.mydoc123.com/p-400168.html