lagen.nu
Emerging and Future Risks Framework - Introductory Manual

Emerging and Future Risks Framework - Introductory Manual

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2010-03-01
Språk
engelska
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.

ENISA EFR Framework March 2010

Introductory Manual

ENISA EFR Framework Introductory Manual

About ENISA

The European Network and Information Security Agency (ENISA) is an EU agency created to advance the functioning of the internal market. ENISA is a centre of excellence for the European Member States and European institutions in network and information security, giving advice and recommendations and acting as a switchboard for information on good practices. Moreover, the agency facilitates contacts between European institutions, the Member States, and private business and industry actors. This work described in this document takes place in the context of ENISA’s Emerging and Future Risk programme.

CONTACT DETAILS

For more information, please contact: e-mail: RiskManagement@enisa.europa.eu Internet: http://www.enisa.europa.eu/

ENISA EFR Framework 5

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

1 INTRODUCTION AND FUNCTION OF THIS MANUAL

The European Network Information Security Agency (ENISA), among its other duties, is tasked with collecting information in order to analyse current and emerging risks which could impact on the availability of electronic systems and networks; or on the confidentiality and integrity of the information which they transmit, store and process. ENISA has therefore undertaken the development of a Framework for the analysis and reporting of emerging and future risks in the area of network information security. ENISA defines emerging risks as those that may have an impact between one and five years in the future; and future risks as those that may have an impact more than five years in the future.

This Manual provides an overview of the processes involved in the Emerging and Future Risks (EFR) Framework. It is intended as an introduction to the EFR Framework and as a guide to how it is used in practice. This Manual has been produced in response to a review of the EFR Framework following its use for the production of a number of reports. It contains modifications and additions to the Framework that have been suggested by its users, as a result of their experience.

The Manual should be read by all those who take part in the EFR Framework process, as a contributor, expert or other stakeholder. Those who read the assessment reports produced by the EFR Framework may also wish to read this Manual in order to understand how EFR assessments are produced. Finally, other groups may wish to use this Manual as an introductory guide to developing their own processes for assessing emerging and future risks.

Note: for detailed and in-depth explanations of the EFR Framework processes; readers are referred to the supporting documentation referenced at annex A.

IoT/RFID Scenario Risk Assessment

Final Report

2 THE EFR FRAMEWORK: CONCEPT AND PURPOSE

The EFR Framework is based around the use of predictive, narrative “scenarios”. The idea of using scenarios in this way was developed in the 1950s and 1960s both in the USA and Europe. Initially “scenario planning”, as it is called, was used by governments for predicting the outcome of social changes; and later by large corporations for commercial planning in the face of market developments. The concept behind scenario planning is essentially simple: it facilitates the telling of realistic stories about possible (or probable) future events, based on extrapolation from present trends.

In scenario planning the effect of (usually two) driving forces on current trends is examined. The extreme (but probable) outcomes of the driving forces are deduced; and “scenarios” are written describing these outcomes. Usually between two and four scenarios are produced and plotted on a two by two matrix that has, as its axes, the selected driving forces. The purpose of scenario planning is to alert decision makers to possible outcomes of current trends and thereby to influence the decisions they make. The use of scenarios, rather than any other form of analysis, is intended to ensure that the extrapolations are both realistic and can be understood and appreciated by the decision makers.

ENISA’s use of scenarios in the EFR Framework is somewhat different in function and purpose from that described above. The concept of developing a narrative scenario, embodying a plausible extrapolation from current trends, has been retained. However, in the EFR Framework, a single technology, or prospective use of that technology, is selected for consideration. This is then built into a unique scenario that describes a situation in the future; in which that technology, or its functionality, has been deployed. For example: previous scenarios developed by ENISA have described the results of being able to gain ubiquitous access to electronic health care information; and the development of technologies that enable all programs and operating systems to be held “in the cloud”, rather than on individual systems.

Once an area of EFR interest has been selected; a narrative story or “scenario” is written. The concepts underlying the story are then subjected to a risk assessment process. This looks at the technology and its use, as described in the narrative, in order to identify possible threats and vulnerabilities. From these, the assessment deduces the potential risk to the assets mentioned by the narrative. The assessment may also describe the management and mitigation of those risks through the deployment of controls. The scenario and its assessment are then written as an ENISA report, and published on the ENISA website.

The purpose of the ENISA EFR Framework is similar to that of classical scenario planning; in that it alerts those reading the report to possible future outcomes of current trends. However, the EFR Framework is both more narrowly targeted and more structured; in that it delivers a reasoned assessment of the risks inherent in the technology and its use.

ENISA EFR Framework 7

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

EFR assessment reports should be read by appropriate target audiences in order to ensure that the risks (both positive and negative) inherent in a technology and its use are recognised and understood. If considered necessary and appropriate, comprehension of the risks will enable decision makers to take appropriate steps to manage and mitigate them, where possible.

IoT/RFID Scenario Risk Assessment

Final Report

3 THE EFR FRAMEWORK PROCESSES

At figure 1, below, is a simplified, outline flow diagram showing the processes of the EFR Framework. These are as follows:

A. Information Management B. Topic Selection C. Scenario Building and Analysis D. Risk Assessment E. Assessment Reporting F. Promotion, Dissemination and Feed-back G. Continuous Improvement.

In the sections below, each of the seven processes is described in more detail. Each section consists of the following elements:

 An overall description of the process.  The objectives of the process.  A flow diagram, showing the steps in the process.  A process description table, showing: - Inputs to each step of the process - A brief description of each step - Outputs from each step - A list of the main contributors to the step. The main contributors being either ENISA staff, ENISA management, members of the EFR Stakeholder Forum, subject matter experts or external contractors, the ENISA Permanent Stakeholders Group (PSG) and the ENISA Management Board.  A list of the technology and tools (such as templates) used in the process.

This introductory manual does not attempt to describe in detail the technology used to support processes, or how the process steps are carried out. Nor does it attempt to define roles and responsibilities in relation to the processes. Detailed descriptions of these can be found in the supporting documentation referenced at annex A.

ENISA EFR Framework 9

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

3.1 A. INFORMATION MANAGEMENT

Information management is central to the operation of the EFR Framework, as can be seen from figure 1. Information management requires the establishment of an efficient knowledge database for the storage of information about technology trends and concerning the operation of the Framework itself. It also requires the implementation and maintenance of an effective collaboration platform, or “portal” to ensure efficient transfer of information between those involved in the process and to ensure quality control. These elements can be seen in figure 2, below.

The objectives of the information management process are as follows:

IoT/RFID Scenario Risk Assessment

Final Report

 To gather information about technology and process trends of relevance to the EFR Framework.  To analyse that information and store it in an information management system.  To disseminate that information, as required, to those involved in the production of EFR assessments.  To manage information flow between those involved in the production of EFR assessments, using appropriate collaboration tools, such as a web-based portal.  To manage information flow between Framework processes; providing quality assurance at each stage during the production of an EFR assessment.  To ensure that information concerning the operation of the EFR Framework processes is gathered and stored appropriately.

Figure 2, below shows the steps in the information management process.

ENISA EFR Framework 11

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

IoT/RFID Scenario Risk Assessment

Final Report

In the table below, the first column shows the steps of the process, as outlined in the process flow diagram above. The second column shows the essential inputs required by the steps. The third column is an outline description of the procedures that take place in the steps; each procedure is numbered. The fourth column indicates the most important outputs from the steps; each output is given a unique reference number (e.g. OA1.1), as these outputs will form inputs into other steps in this process, or other processes. The final column suggests those who will contribute to the steps.

Step Input Description Output Contributors

ENISA EFR Framework 13

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

Step Input Description Output Contributors

IoT/RFID Scenario Risk Assessment

Final Report

Step Input Description Output Contributors

The following technology and tools are used in this process:

 A knowledge database, allowing structured storage of EFR information, technology and process trend data etc.  A web-based portal, hosted on the ENISA website, including: - A full description of the portal (termed a “collaboration platform”). - Instructions for use of the portal (including roles and responsibilities).

3.2 B. TOPIC SELECTION

The process of topic selection for an EFR assessment report follows an annual cycle. The first phase of this is to identify broad areas of concern in relation to emerging and future risks as identified by the

ENISA EFR Framework 15

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

previous year’s trend analysis, with input from ENISA’s work programme, the EFR Stakeholder Forum and ENISA’s Permanent Stakeholder Group (PSG).This is then subject to a call for scenario proposals, published on the ENISA website in December. Eligible scenarios are submitted to the PSG for consideration and ranking. The top-ranked proposals will be chosen for EFR Framework assessment. A business case will be produced for each chosen scenario. This will identify the scope, target audience and objectives for the assessment report, including the need to identify risk treatments, where appropriate.

The objectives of topic selection are as follows:  To identify and select annually appropriate topic areas for EFR assessment reports.  To ensure that an appropriate target audience is identified for the topics selected.  To ensure that the scope of each assessment report has been correctly identified and fully defined.  To ensure that the objectives for the assessment reports have been defined; in terms of likely outcomes and potential actions consequent on publication of the reports.

Figure 3, below, shows the steps in the topic selection process.

IoT/RFID Scenario Risk Assessment

Final Report

In the table below, the first column shows the steps of the process, as outlined in the process flow diagram above. The second column shows the essential inputs required by the steps. The third column is an outline description of the procedures that take place in the steps; each procedure is numbered.

ENISA EFR Framework 17

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

The fourth column indicates the most important outputs from the steps; each output is given a unique reference number (e.g. OA1.1), as these outputs will form inputs into other steps in this process, or other processes. The final column suggests those who will contribute to the steps.

Step Input Description Output Contributors

IoT/RFID Scenario Risk Assessment

Final Report

Step Input Description Output Contributors

ENISA EFR Framework 19

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

Step Input Description Output Contributors

The following technology and tools are used in this process:

 A knowledge database, allowing structured storage of EFR information, technology and process trend data etc.

IoT/RFID Scenario Risk Assessment

Final Report

 A web-based portal, hosted on the ENISA website.  “Call for scenario proposals” template (see annex B).  An EFR assessment business case template. (see annex C).

3.3 C. SCENARIO BUILDING AND ANALYSIS

Building and analysing the scenario involves taking the proposed scenario from the topic selection process and, through the use of subject matter experts, turning it into an agreed narrative form and identifying the critical components of the narrative. These components will be realistic and will include a timeframe over which it happens, and an agreed set of actors, technologies applications and processes. The data at potential risk will be defined and agreed, as will the social, political and technical drivers that have led to the scenario. Once the narrative structure and its content have been defined, analysed and agreed, these will be quality assured and passed to the risk assessment process.

The objectives of scenario building and analysis are as follows:  To select appropriate subject matter experts to collaborate on the building, analysis and assessment processes.  To determine the nature of the scenario.  To agree the scenario narrative.  To agree the timeframe, location, actors, technology and applications, data and drivers in the scenario narrative.  To document the agreed scenario build and analysis and obtain sign-off.

Figure 4, below, shows the steps in the scenario building and analysis process.

ENISA EFR Framework 21

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

In the table below, the first column shows the steps of the process, as outlined in the process flow diagram above. The second column shows the essential inputs required by the steps. The third column is an outline description of the procedures that take place in the steps; each procedure is numbered. The fourth column indicates the most important outputs from the steps; each output is given a unique reference number (e.g. OA1.1), as these outputs will form inputs into other steps in this process, or other processes. The final column suggests those who will contribute to the steps.

IoT/RFID Scenario Risk Assessment

Final Report

Step Input Description Output Contributors

ENISA EFR Framework 23

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

Step Input Description Output Contributors

IoT/RFID Scenario Risk Assessment

Final Report

Step Input Description Output Contributors

The following technology and tools are used in this process:

 A knowledge database, allowing structured storage of EFR information, technology and process trend data etc.  A web-based portal, hosted on the ENISA website.  A scenario building and analysis template (see annex D).

3.4 D. RISK ASSESSMENT

This process identifies the assets (both tangible and intangible) described in the scenario that are at potential risk, threats to those assets implied by the scenario and the vulnerabilities that are inherent both in the technology used in the scenario and in the way that it is deployed by the identified actors in the scenario. The potential impact that threats could have on the assets (financial, political, physical and human), are agreed. The risks associated with the scenario are subject to an assessment using a chosen methodology. The analysis is conducted by a risk assessment expert and the results are fully documented; indicating the details of the risk identification, analysis and evaluation. If the scenario business case calls for it (depending on its nature) an evaluation of risk treatment is also carried out, looking at potential options for actions to be taken to manage or mitigate the identified risks.

The objectives of risk assessment are as follows:

ENISA EFR Framework 25

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

 To identify the elements inherent in the scenario that are required to perform a risk assessment on that scenario. These include: - Threats; - Vulnerabilities; - Assets at risk; - Potential impact on those assets.  To select an appropriate risk assessment methodology.  To analyse the risks and evaluate them.  To identify a risk treatment plan, if called for by the business case.

Figure 5, below, shows the steps in the risk assessment process.

IoT/RFID Scenario Risk Assessment

Final Report

ENISA EFR Framework 27

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

In the table below, the first column shows the steps of the process, as outlined in the process flow diagram above. The second column shows the essential inputs required by the steps. The third column is an outline description of the procedures that take place in the steps; each procedure is numbered. The fourth column indicates the most important outputs from the steps; each output is given a unique reference number (e.g. OA1.1), as these outputs will form inputs into other steps in this process, or other processes. The final column suggests those who will contribute to the steps.

Step Input Description Output Contributors

IoT/RFID Scenario Risk Assessment

Final Report

Step Input Description Output Contributors

ENISA EFR Framework 29

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

Step Input Description Output Contributors

IoT/RFID Scenario Risk Assessment

Final Report

Step Input Description Output Contributors

The following technology and tools are used in this process:

 A web-based portal, hosted on the ENISA website.  A scenario buiding and analysis template (see annex D).  A database of risk assessment experts.  A database of risk assessment methodologies.  An EFR assessment business case template (see annex C).  A risk assessment template (see annex E).

3.5 E. ASSESSMENT REPORTING

This process provides the interface between the EFR assessment Framework and the target audience for assessment reports. The target audience(s) will have been identified as part of the business case, as will the objectives for the report. The Assessment Reporting process should decide the format for the report (based on a standard template). The process ensures that the report is written in such a way as to address the target audience and to meet its objectives. The process also ensures that the report is produced to a consistently high quality and standard. Finally, the process ensures that the report is published, usually on the ENISA website, within an agreed timeframe.

ENISA EFR Framework 31

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

The objectives of assessment reporting are as follows:  To ensure that assessment reports are written in a standard EFR format, clearly identifying them as EFR assessment reports.  To ensure that reports are written in such a way as to clearly address their target audience and to meet the objectives stated in their business cases.  To ensure that the assessment reports are written to a consistently high standard of clarity, readability and accuracy.  To ensure that assessment reports are published (on the ENISA website) in a timely fashion.

Figure 6, below, shows the steps in the assessment reporting process.

IoT/RFID Scenario Risk Assessment

Final Report

ENISA EFR Framework 33

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

In the table below, the first column shows the steps of the process, as outlined in the process flow diagram above. The second column shows the essential inputs required by the steps. The third column is an outline description of the procedures that take place in the steps; each procedure is numbered. The fourth column indicates the most important outputs from the steps; each output is given a unique reference number (e.g. OA1.1), as these outputs will form inputs into other steps in this process, or other processes. The final column suggests those who will contribute to the steps.

Step Input Description Output Contributors

IoT/RFID Scenario Risk Assessment

Final Report

Step Input Description Output Contributors

ENISA EFR Framework 35

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

Step Input Description Output Contributors

The following technology and tools are used in this process:

 A web-based portal, hosted on the ENISA website.  A scenario building and analysis template (annex D).  An EFR assessment business case template (annex C).  A risk assessment spreadsheet (annex E).  An EFR assessment report template (annex F).  EFR Knowledge database.

3.6 F. PROMOTION, DISSEMINATION AND FEEDBACK

The purpose of this process is to ensure that assessment reports reach the designated target audience and meet the objectives identified in the business case. This is achieved by defining key elements of the promotion programme; including the launch method, news releases surrounding publication, distribution and feedback. The process also identifies and maintains data on key communication channels for the report. All these issues are documented in a dissemination, promotion and feedback plan, and approval obtained for it. The process ensures that the ENSIA website will meet report

IoT/RFID Scenario Risk Assessment

Final Report

download requirements and identifies any modifications that may be required. If necessary, external promotion resources are identified and costed. Clear feedback requirements, following publication of reports, are identified and developed where necessary; as are methods to capture feedback and measure effectiveness of report (e.g. number of downloads and citations etc).

Note: promotion activities will be carried out by the appropriate department within ENISA, in cooperation with the risk assessment and management group.

The objectives of the promotion, dissemination and feedback process are as follows:  To ensure that the EFR assessment reports are read by the target audience agreed in the business case.  To enable a wider range of audience to be identified and reached.  To identify the most appropriate methods for distribution of the EFR assessment reports.  To capture feedback and measure effectiveness in a structured manner.

Figure 7, below, shows the steps in the promotion, dissemination and feedback process.

ENISA EFR Framework 37

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

IoT/RFID Scenario Risk Assessment

Final Report

In the table below, the first column shows the steps of the process, as outlined in the process flow diagram above. The second column shows the essential inputs required by the steps. The third column is an outline description of the procedures that take place in the steps; each procedure is numbered. The fourth column indicates the most important outputs from the steps; each output is given a unique reference number (e.g. OA1.1), as these outputs will form inputs into other steps in this process, or other processes. The final column suggests those who will contribute to the steps.

Step Input Description Output Contributors

ENISA EFR Framework 39

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

Step Input Description Output Contributors

IoT/RFID Scenario Risk Assessment

Final Report

Step Input Description Output Contributors

ENISA EFR Framework 41

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

Step Input Description Output Contributors

The following technology and tools are used in this process:

 A web-based portal, hosted on the ENISA website.  An EFR assessment business case template.  An EFR assessment report template.  A promotion plan template.  A launch plan template.  Feedback templates.  Measurement of downloads, citations of report etc.

3.7 G. CONTINUOUS IMPROVEMENT

The purpose of this process is to ensure that the EFR assessment reports produced by the EFR Framework achieve a consistently high quality and meet the objective of engaging with target audiences to alert them to EFR issues in a realistic and clear way; enabling them, where necessary and appropriate, to take management and mitigation action. The process does this by assessing feedback data, and identifying both positive elements and areas for improvement in both reports and the Framework. The process uses measurements of report effectiveness to ensure that the report has met its initial business case, for example in terms of reaching the identified target audience. The process reports on feedback and effectiveness and ensures that changes are made to the Framework, where required. The process also ensures that future reports take into account the feedback received. Where necessary and appropriate, the process also identifies the timing, content, participants and recipients for follow-up reports and other activities, such as workshops. The process ensures that these activities are conducted in a timely and effective fashion and that follow-up reports are documented and disseminated, where appropriate.

IoT/RFID Scenario Risk Assessment

Final Report

The objectives of the continuous improvement process are as follows:  Assess feedback and effectiveness measurements to understand usefulness of the report  Capture expertise and knowledge for future reports  Identify appropriate changes that may be required to the Framework.  Identify related follow-up reports and activities to extend the value of the report.

Figure 8 below, shows the steps in the continuous improvement process.

ENISA EFR Framework 43

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

IoT/RFID Scenario Risk Assessment

Final Report

In the table below, the first column shows the steps of the process, as outlined in the process flow diagram above. The second column shows the essential inputs required by the steps. The third column is an outline description of the procedures that take place in the steps; each procedure is numbered. The fourth column indicates the most important outputs from the steps; each output is given a unique reference number (e.g. OA1.1), as these outputs will form inputs into other steps in this process, or other processes. The final column suggests those who will contribute to the steps.

Step Input Description Output Contributors

ENISA EFR Framework 45

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

Step Input Description Output Contributors

IoT/RFID Scenario Risk Assessment

Final Report

Step Input Description Output Contributors

The following technology and tools are used in this process:

 A web-based portal, hosted on the ENISA website.  An EFR assessment business case template (annex C).  A feedback report template.  The EFR knowledge database.

ENISA EFR Framework 47

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

4 ANNEX A: EFR FRAMEWORK, SUPPORTING DOCUMENTATION

 Emerging and Future Risks Workflow (Final). Jeremy Burton, Pete Burnap and Anas Tawileh. [Undated].  Emerging and Future Risks Executable Workflow UML Description. Technical department of ENISA risk management in cooperation with the: VTT Technical Research Centre of Finland. November 2008.  EFR Framework Handbook. Technical department of ENISA risk management in cooperation with Atos Origin, Spain. [Draft]. March 2009.  EFR Collaboration Platform, User Guide. Technical department of ENISA risk management in cooperation with Atos Origin, Spain. [Draft]. September 2009.

IoT/RFID Scenario Risk Assessment

Final Report

5 ANNEX B: CALL FOR SCENARIO PROPOSALS TEMPLATE

Submission Details

Those interested in submitting a proposal for an emerging and future risk assessment are asked to complete the following online submission template.

Proposal related to (select one):

 Topic Area 1  Topic Area 2  Topic Area 3 etc.

Short, descriptive title for the proposal *e.g. “Cyberbullying in 2012”+

Brief outline of the proposed scenario (Up to 500 Words)

An assessment of the significance of the technology and its application, as outlined in the proposed scenario

ENISA EFR Framework 49

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

Target audience(s) for the assessment report *e.g. “legislators”+

Brief description of the benefits likely to emerge from this assessment report

Suggestions of individuals who might be willing to support and contribute to this assessment

IoT/RFID Scenario Risk Assessment

Final Report

Contact details of the individual responsible for submitting this proposal

Title (Dr., Mr., Ms., Miss, Mrs)

First Name

Last Name

Job title

Organisation (include also a brief description)

Address

Phone

Email

To be eligible for consideration, proposals should be submitted by:  Member States (including any public organization representing the Member State’s interest)  European Commission and other EU Institutions  ENISA Management Board  ENISA Permanent Stakeholders Group  ENISA National Liaison Officers (see list)  Any other public stakeholder (e.g. consumer organisations, associations etc.)  Industry.

It should be noted that the assessment will not consider proprietary technologies and, as an ENISA deliverable, will become public material published on the ENISA web-site.

ENISA EFR Framework 51

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

The deadline for proposals is: [insert date].

Selection Process

Eligible proposals will be evaluated for each category, according to the following criteria:  Completeness of the submission.  Relevance and adequacy of the proposed scenario.  Evidence of benefit from carrying out the assessment.  Nature of the identified target audience.

We hope to select up to 20 proposals on the basis of these criteria. The selected proposals will be submitted (anonymously) to the Permanent Stakeholders’ Group; who will be asked to rank them in order of their potential to generate significant and valuable assessment reports. The top two proposals in ranked order will be selected to become emerging and future risk assessment projects for [insert year]. For further information please contact us at: RiskManagement@enisa.europa.eu

IoT/RFID Scenario Risk Assessment

Final Report

6 ANNEX C: EFR ASSESSMENT BUSINESS CASE TEMPLATE

Title of the Scenario

Scope of the assessment

Target audience

Objectives and outcomes expected from publication (including benefits for target audience)

Associated work and other initiatives

Indication of resources required

ENISA EFR Framework 53

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

7 ANNEX D: SCENARIO BUILDING AND ANALYSIS TEMPLATE

Structure of the template

The template is structured as follows:  Introductory part, where a general overview and the background to the scenario is provided  The Scenario description, including the following information: - Scenario type: explorative (what can happen) or predictive (what will happen) - Scenario raw description: this is where the scenario is described in free text. The intended text in italics provides more technical information on how certain activities are performed. These details are not necessarily those of which actors are fully aware as they happen in the background. - Assumptions: Any assumptions made while formulating the scenario.  Analysing the scenario – This section contains a number of fields, with information we would like to know to proceed with the risk assessment as a next step.  A Glossary – Lists the abbreviations used throughout the text, where important terms like “threats”, “vulnerabilities”, etc. are defined.  Other information where more information not specified in the table above could be specified, or figures and pictures added, etc.  References, where all references used for completion of the tables should be listed.

IoT/RFID Scenario Risk Assessment

Final Report

[Title of the scenario]

Type of scenario

[“predictive” or “explorative” to indicate the nature of the scenario]

Raw description of scenario

[who does what or what happens. The intended text in italics provides more technical information on how certain activities are performed. These details are not necessarily fully understood by the actors

and they happen in the background.]

Assumptions [any assumptions made while writing the scenario flow. The assumptions’ field is a place holder for information that may concern generic information about relevant legislation, devices, applications, participants, etc.]

Analysing the scenario

Timeframe

[when the scenario takes place]

Location

[where: Home / work / public

ENISA EFR Framework 55

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

space...]

Actors 

[who: entities relevant to the scenario and describe their roles and goals. These most include humans and organisations but not IT systems.]

Technologies /  devices

[technologies / devices used in the scenario]

Applications 

[applications used in the scenario]

Data

[information that is collected, or flows through the network, or is being stored and further processed]

Drivers

IoT/RFID Scenario Risk Assessment

Final Report

[key drivers behind the scenario: socio-

economic, political,

environmental or personal motivation...]

Glossary / Aid Other information

[You may provide here other information you consider relevant and cannot be covered in the fields above, e.g. images etc.]

References

ENISA EFR Framework 57

Introductory Manual

Identifying emerging and future risks in a future IoT/RFID air travel scenario

8 ANNEX E: RISK ASSESSMENT TEMPLATE

A. Assets

[tangible or intangible: any devices, technologies, applications, processes, data of value ]

ID Asset Description or reference to above Owner Perceived described elements Asset

[involved actors /

Value

organisations]

Intangible

A1. A2.

Tangible

A3. A4.

B. Vulnerabilities

[List of the vulnerabilities of the tangible / intangible assets with their value]

No. Vulnerability Vulnerability Value Description

V1. V2. V3. V4.

NOTE: When you make any change / addition to the vulnerabilities, do not forget to update the next table (the mapping between assets and vulnerabilities)!

IoT/RFID Scenario Risk Assessment

Final Report

C. Assets and Vulnerability Mapping [identifying vulnerabilities from the list above for each asset; note that vulnerability value might differ from asset to asset]

Asset Assets Vulnerability Description Vulnerability Value ID

A1

D. Threats

[List of the threats with their value]

ID Threat Threat Value

Description

T1. T2.

Other information

[You may provide here other information you consider relevant and cannot be covered in the fields above, e.g. images etc.]

References

Fotnoter

  1. Legal notice
  2. Notice must be taken that this publication represents the views and interpretations of the authors and editors, unless stated otherwise. This publication should not be construed to be an action of ENISA or the ENISA bodies unless adopted pursuant to the ENISA Regulation (EC) No 460/2004. This publication does not necessarily represent state-of the-art and it might be updated from time to time. Third-party sources are quoted as appropriate. ENISA is not responsible for the content of the external sources including external websites referenced in this publication. This publication is intended for educational and information purposes only. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. Reproduction is authorized provided the source is acknowledged. © European Network and Information Security Agency (ENISA), 2010
  3. ENISA EFR Framework Outline Process Flow EFR Framework
  4. A. Information Management
  5. C. Scenario D. Risk E. Assessment B. Topic Selection Building and Assessment reporting Analysis
  6. Business Case
  7. F. Promotion, EFR Report Dissemination and Feedback
  8. G. Continuous Improvement
  9. FIGURE 1: EFR FRAMEWORK: OUTLINE PROCESSES
  10. 3.1.2 PROCESS STEPS
  11. EFR Framework: Information Management Process Flow New Technology and Process Data
  12. EFR Start EFR A1. Information Knowledge Framework collection database
  13. A3. Establish and A2. Trend analysis maintain the portal
  14. B. Topic A4. Use portal Selection
  15. Topic OK? No
  16. C. Scenario A4. Use portal Building and Analysis
  17. Scenario/ No Analysis OK?
  18. EFR G. Knowledge D. Risk Continuous A4. Use portal database Assessment Improvement [OA1.4]
  19. A4. Use portal Assessment No OK?
  20. F. Marketing, E. Dissemination Assessment and Feedback Reporting
  21. FIGURE 2: INFORMATION MANAGEMENT PROCESS FLOW DIAGRAM
  22. 3.1.3 PROCESS DESCRIPTION TABLE
  23. 1 List of relevant information List of information sources (Websites; sources [OA1.1]. publications; journals etc.) compiled. List of subject matter experts Information from 2.List of appropriate subject [OA1.2]. external sources matter experts (with contact about new details) compiled. Compiled A1. information on new ENISA staff. technologies and 2. Sources regularly examined Information technology and Subject matter processes. for information of relevance Collection processes, with experts. Commentary to EFR Framework. expert commentary from subject 3. Information collected and where appropriate matter experts. comment received from [OA1.3] passed to subject matter experts. step A2 and stored 4. Compiled and commented in EFR knowledge information passed to EFR database [OA1.4]. knowledge database.
  24. 1 Information about the selection of a topic for an assessment report is gathered.
  25. 2 Relevant information (with commentary) retrieved from Analysed Information on the EFR knowledge database. technology trend selected scenario ENISA staff. A2. Trend 3. Technology and process information topic [OB1.1]. Subject matter Analysis trends related to the topic [OA2.1] passed to OA1.3. from step experts. analysed, with assistance processes B, C and A1 from appropriate subject D. matter experts. 4. Analysed trend information passed to scenario building process (C) and scenario analysis process (D) 1. ENISA selects appropriate technology and processes to develop a portal to facilitate collaborative working between ENISA staff and other contributors to the EFR Framework. Note: this is a one-off process. 2. The technology is implemented, processes are ENISA staff. A3. Establish Appropriate devised and a handbook is A maintained portal External and maintain technology and produced. with instructions contractors the portal processes 3. Access to the portal, the for use [OA3.1] where necessary handbook and suitable and appropriate instruction is given to all contributors to the EFR Framework. 4. The portal is maintained and developed to ensure efficient and effective collaboration in the production of EFR assessment reports.
  26. 1 For each process in the EFR Framework, the portal is used to coordinate action and to communicate information and working documents. 2. For each process the portal is used to perform quality assurance of the process outputs. Quality assurance is provided by either the EFR Process output Stakeholder Forum or ENISA checked for quality ENISA staff. staff, as appropriate. [OA4.1]. OA3.1. Output Subject matter A4. Use the 3. If the process output is of Information about from processes B, experts. EFR portal appropriate quality, the process operation C, D, E, F and G. Stakeholder output is passed to the next stored in EFR Forum. process. knowledge 4. If the process output is not database [OA4.2]. of appropriate quality, recommendations for quality improvement are made and appropriate contributors revisit the output. 5. All relevant information about the operation of the processes is stored on the EFR knowledge database.
  27. TABLE 1: INFORMATION MANAGEMENT PROCESS DESCRIPTION
  28. 3.1.4 TECHNOLOGY AND TOOLS
  29. 3.2.2 PROCESS STEPS
  30. ENISA EFR Topic Selection Process
  31. Suggested topic areas
  32. B1. Analysis of Appropriate START potential topic No Rejection topic area? areas
  33. ENISA work Top topic areas programme [OB1.1]
  34. EFR Topic templates ENISA B2. Potential topic Knowledge [OB2.1] resource selection database data [OA1.4]
  35. B3. Call for Scenario B4. Eligible scenario proposals [OB3.1] scenarios proposals approved
  36. Final topic list B5. PSG ranking [OB5.1] process
  37. B6. Business case production
  38. Business case B7. Management [OB6.1] approval
  39. Approved C. Scenario business case Building and [OB7.1] Analysis process
  40. FIGURE 3: TOPIC SELECTION PROCESS FLOW DIAGRAM
  41. 3.2.3 PROCESS DESCRIPTION TABLE
  42. 1 All ENISA contributors and stakeholders are encouraged to suggest topics for EFR assessments. Suggestions for topic areas from 2. Topic suggestions are analysed in ENISA relation to trend data from the EFR stakeholders knowledge database. and
  43. 3 Potential topic areas are List of top topic All ENISA contributors. B1. Analysis analysed in relation to work areas areas for EFR contributors and of potential Trend analysis planned for the coming year under assessment stakeholders. topic areas data from EFR the ENISA work programme. [OB1.1] passed ENISA staff. knowledge 4. Suggestions which are not in to step B2. database tune with trend analysis and/or the [OA1.4]. ENISA work programme are ENISA work rejected. programme. 5. A list of top topic areas for potential EFR assessment is compiled and passed to step B2. 1. Generic template call for potential scenarios to be suggested by ENISA contributors and stakeholders compiled. Scenario call 2. Number of EFR assessments List of top topic template possible during the year B2. Potential areas [OB1.1] populated with determined in light of available topic from step B1. top topic areas ENISA staff ENISA resources. selection ENISA resource [OB2.1] and 3. Top topic areas examined and data. passed to step prioritised in light of available B3. ENISA resources.
  44. 4 Calling template populated with selected priority topic areas and passed to step B3.
  45. 1 Instructions for completing proposal template, including list of those eligible to make proposals, drawn up and proposal deadline Web-enabled decided. submission Scenario call 2. In December, template forms for B3. Call for ENISA staff. template published as a web-enabled form scenario scenario Invited, eligible, [OB2.1] from on ENISA website. proposals proposals contributors step B2. 3. ENISA stakeholders and eligible [OB3.1} contributors encouraged to make completed by scenario proposals. contributors. 4. Proposals received by the selected deadline (end of January in the following year). 1. Submitted proposal forms examined to check for eligibility, appropriateness and completeness. 2. Eligible, complete and List of suitable B4. Eligible Submission appropriate proposals examined scenario scenarios forms [OB3.1] for suitability of proposed proposals ENISA staff. approved from step B3. scenarios to be used as the basis [OB4.1] to step for an EFR assessment report. B5. 3. List of eligible, appropriate and suitable scenario proposals complied and sent to step B5. 1. ENISA agrees rating process for proposals. Potential parameters include: relevance to potential target audience; contribution to ENISA’s aims; and potential List of proposals positive outcome from assessment. List of suitable with scores B5. PSG scenario 2. List of suitable scenario from PSG and ranking ENISA staff. PSG. proposals proposals submitted to ENISA ranking [OB5.1], process [OB4.1]. Permanent Stakeholders Group passed to step (PSG). B6. 2. PSG asked to rate listed proposals using agreed parameters. 3. Proposals ranked according to
  46. scores determined following outcome of PSG rating. 4. Ranked list of proposals passed to step B6. 1. ENISA staff prepare a business case for the top-ranked proposals, using a business case template and information from EFR Knowledge database. Ranked 2. Business case includes: proposals consideration of scope of Completed B6. Business [OB5.1] from assessment to be performed; business case case ENISA staff. step B5. potential target audience for [OB6.1] passed production EFR Knowledge assessment; objectives and to step B7. database. outcomes (including benefit) of publication of report; relevant associated work and initiatives; indication of resources required. 3. Completed business case passed to step B7. 1. Business cases for EFR assessment report proposals agreed by ENISA senior Business cases management. with ENISA ENISA senior 2. Appropriate resource allocation management management. B7. Business case agreed by senior management. approval ENISA Management [OB6.1] from 3. Business cases, with note of [OB7.1] passed Management approval step B6. resources allocated, may be passed to process C Board (if to ENISA Management Board for (Scenario necessary). approval if necessary. Building and Analysis). 4. Approved business cases passed to process C. (Scenario Building and Analysis).
  47. TABLE 2: TOPIC SELECTION PROCESS DESCRIPTION
  48. 3.2.4 TECHNOLOGY AND TOOLS
  49. 3.3.2 PROCESS STEPS
  50. ENISA EFR Framework: Scenario Building and Analysis Process B. Topic Selection process
  51. Selected topic [OB7.1]
  52. List of C1. Subject matter subject expert selection matter experts
  53. EFR C2. Determine Knowledge nature of scenario Scenario template database and agree [OA1.4] narrative
  54. C3. Agree timeframe, location, actors, technology etc.
  55. C4. Make C4. Document Document OK? No necessary scenario and QA changes
  56. Documented Scenario [OC4.1] Yes
  57. D. Risk Assessment process
  58. FIGURE 4: SCENARIO BUILDING AND ANALYSIS PROCESS FLOW DIAGRAM
  59. 3.3.3 PROCESS DESCRIPTION TABLE
  60. 1 Selected topics examined in
  61. the light of information about
  62. technology trends from the EFR
  63. knowledge database.
  64. 2 List of ENISA subject matter Selected experts examined to determine Contact details scenario topic appropriate involvement in and meeting C1. Subject [OB7.1] from ENISA staff. suggested scenario topic. arrangements for matter expert Topic Selection Subject matter 3. Subject matter experts experts [OC1.1] selection (process B). experts. approached and timetable for passed to next List of subject scenario building meeting(s) step. matter experts. agreed.
  65. 4 Contact details of chosen
  66. experts and meeting
  67. arrangements documented and
  68. passed to step C2.
  69. 1 Selected scenario topic
  70. discussed at meeting of experts
  71. (note: meetings can be real or
  72. virtual, although real meetings
  73. are recommended).
  74. 2 Experts are fully briefed by
  75. Contact details ENISA staff on the EFR Scenario template and meeting Framework processes, including with nature, arrangements risk assessment methods. C2. assumptions and for experts 3. Technology trends relevant to Determine narrative [OC2.1] [OC1.1]. the scenario (from EFR ENISA staff. nature of to next step. Selected Knowledge database) examined. Subject matter scenario and Agreed timing scenario topic 4. Nature of scenario (predictive experts. agree and nature of [OB7.1]. or explorative) and assumptions narrative next scenario EFR Knowledge underlying the scenario agreed. build meeting database 5. Narrative flow of the scenario, [OC2.2]. [OA1.4]. discussed and agreed.
  76. 6 Scenario template built with
  77. agreed nature, assumptions and
  78. narrative.
  79. 7 Agreement of timing and
  80. nature of next meeting to
  81. complete build of scenario
  82. template.
  83. 1 Scenario narrative etc. discussed at meeting of experts (note: meetings can be real or virtual, although real meetings are recommended). Scenario template 2. Technology trends relevant to Scenario template C3. Agree [OC2.1} and the scenario (from EFR with completed ENISA staff. timeframe, agreed meeting Knowledge database) examined. location, actors, build details Subject matter [OC2.2]. 3. Location, timeframe, actors, technology etc. [OC3.1] passed to experts. EFR Knowledge technologies and systems, data at next step. database potential risk and socio- [OA1.4]. economic, political etc. drivers for the scenario agreed. 4. All elements documented in the scenario template and passed to the next step.
  84. 1 ENISA staff ensure that scenario template has been completed with build and analysis details and has captured all scenario requirements. 2. ENISA staff pass checked Scenario C4. Document Scenario ENISA staff. template to EFR Stakeholder template, quality scenario and template EFR Stakeholder Forum for quality assurance. assured, [OC4.1] QA [OC3.1] Forum. 3. EFR Stakeholder Forum to process D. examine scenario template and agree changes (if required). 4. Quality assured scenario build template passed to Scenario Analysis (process D).
  85. TABLE 3: SCENARIO BUILDING AND ANALYSIS PROCESS DESCRIPTION
  86. 3.3.4 TECHNOLOGY AND TOOLS
  87. 3.4.2 PROCESS STEPS
  88. ENISA EFR Framework: Risk Assessment Process
  89. C. Scenario Building and Analysis process
  90. Scenario template [OC4.1]
  91. ENISA risk ENISA risk D1. Choose assessment assessment appropriate expert expert methodologies and methodology database
  92. D2. Identify assets, threats, vulnerabilities and impacts
  93. Complete scenario template [OD2.1]
  94. Risk assessment template D3. Perform risk (spreadsheet) assessment
  95. D4. Determine risk Business case treatment [OB7.1] requirement
  96. D4. Assess risk Risk Yes treatment treatment?
  97. D5. Document risk D5. Make assessment (and Document OK? No necessary risk treatment) and changes QA
  98. Documented risk assessment (and treatment) [OD5.1] Yes
  99. E. Assessment Reporting process
  100. FIGURE 5: RISK ASSESSMENT PROCESS FLOW DIAGRAM
  101. 3.4.3 PROCESS DESCRIPTION TABLE
  102. 1 ENISA selects an appropriate expert to lead the risk assessment process. 2. The scenario build and analysis template is examined by the chosen risk assessment expert, in order to identify an appropriate risk assessment ENISA list of risk methodology. assessment 2. The appropriate experts. Brief introduction D1. Choose methodology is selected. Either Scenario template to chosen ENISA staff. appropriate from the ENISA risk assessment [OC4.1]. methodology Risk assessment expert and methodologies database or ENISA risk [OD1.1] passed to expert methodology from any other source. step D2. assessment 3. Reasons for the selection of methodologies the methodology are database. documented and a brief introduction to the methodology for non-experts is produced. 4. Introduction to chosen methodology and completed scenario template passed to step E2.
  103. 1 A meeting of subject matter experts (note: meetings can be real or virtual, although real meetings are recommended),.is led by the risk assessment expert and determines the significant assets that are at risk in the described scenario. Both tangible and intangible assets are identified and their role in the scenario is clarified. Asset ownership and value (on a scale of 1 to 10) is identified. 2. Vulnerabilities related to identified assets are agreed and their significance assessed (high, medium or low). 3. Potential threats are identified. The vulnerabilities that they can exploit are D2. Identify recorded, as is the nature of the Completed Risk assessment assets, Scenario template threat and an assessment (high, scenario template expert. threats, from previous medium or low). [OD2.1] passed to Subject matter vulnerabilities process [OC4.1]. 4. Controls for the threats and next step experts and impacts vulnerabilities are identified. The controls are described, as is their mitigating or management action. The effectiveness of the controls is assessed (high, medium or low).
  104. 5 The potential impact on the scenario’s assets is determined. Socio-political, legal and ethical, financial and economic, organisational and technical and human impacts are considered.
  105. 6 Acceptable risk levels are identified, as are any assumptions made and the rationale behind the choices.
  106. 7 All information is documented in the scenario template and passed to next step.
  107. 1 Subject matter expert group
  108. given introduction to chosen
  109. methodology. and methodology
  110. explained. Note: this can also Introduction to be done in the scenario build chosen and analysis process (step C2). methodology Spreadsheet with 3. Expert group, led by risk Risk assessment D3. Perform [OE1.1]. risk identification, assessment expert, conduct risk expert. risk Completed analysis and assessment, based on scenario Subject matter assessment scenario template evaluation analysis, using chosen experts. [OD2.1]. [OD3.1] methodology. Risk assessment 4. Risks identified, analysed and spreadsheet. evaluated using risk assessment
  111. spreadsheet.
  112. 5 Spreadsheet passed to step
  113. 1 Subject matter expert group
  114. determine if risk treatment
  115. policy is in line with
  116. requirements of business case.
  117. 2 If the decision is to assess a Risk assessment D4. Risk assessment risk treatment, risk assessment spreadsheet with Risk assessment Determine spreadsheet expert should lead the subject risk treatment expert. requirement [OD3.1]. matter expert group to assessment Subject matter and assess Business case determine potential actions to where experts. risk treatment [OB7.1] manage and mitigate the appropriate
  118. identified, evaluated risks. [OD4.1]
  119. 3 The risk assessment
  120. spreadsheet should be
  121. completed and passed to step
  122. 1 ENISA staff should check the risk assessment spreadsheet to ensure that all necessary steps in the methodology have been carried out correctly. 2. ENISA staff should ensure D5. that all relevant issues have Document Documented risk been documented (including risk assessment (and Risk assessment decision on risk treatment). assessment treatment) ENISA staff. template [OD4.1] 3. If any issues are unclear or (and risk [OE4.1] to incomplete, the subject matter treatment) process E. experts should be asked to reand QA visit the issue(s). The completed risk assessment (and risk treatment where appropriate) should be fully documented and passed to F Assessment Reporting process.
  123. TABLE 4: RISK ASSESSMENT PROCESS DESCRIPTION
  124. 3.4.4 TECHNOLOGY AND TOOLS
  125. 3.5.2 PROCESS STEPS
  126. ENISA EFR Framework: Assessment Reporting Process
  127. D. Risk Assessment process
  128. Documented risk assessment (and treatment) [OD5.1]
  129. Complete scenario E1. Create EFR assessment template [OD2.1] assessment report report template template
  130. E1. Document Business case E2. Write report report template [OB7.1] for target audience with scenario and and objectives assessment
  131. Draft EFR assessment report
  132. E3. QA report for E3. Make clarity, accuracy Report OK? No necessary etc. changes
  133. E4. Obtain management agreement
  134. EFR Assessment Report [OE4.1]
  135. EFR Knowledge database [OA1.4]
  136. G. Promotion, Dissemination and Feedback process
  137. FIGURE 6: ASSESSMENT REPORTING PROCESS FLOW DIAGRAM
  138. 3.5.3 PROCESS DESCRIPTION TABLE
  139. 1 An individual should be given overall responsibility for production of the assessment report, as designated report owner (or project manager). 2. An assessment report template should be created, based on the Documented common features of previous EFR Populated EFR ENISA staff. risk assessment E1. Document assessment reports. assessment Designated [OD5.1]. report 3. The report template should be report template report owner Scenario template populated with the built scenario [OE1.1] to step (project template and analysis (data from the E2. manager). [OD2.1].. scenario template) and with the risk evaluation (data from the documented risk assessment). 4. The report template should be checked to ensure that it contains all relevant data and passed to step F2 1. The designated report owner (project manager) should appoint an appropriate report author (this could be a professional E2. Write Report template Draft EFR Report owner writer, if resources permit, or a report for [OE1.1]. assessment (project member of ENISA staff). target Business case report [OE2.1] to manager). 2. The appointed report author audience [OB7.1] next step. Report author. should draft the EFR assessment report, based on the populated assessment report template 3. The report owner (project
  140. manager) should ensure that the draft EFR assessment report is written in such a way as to address the target audience, as agreed in the business case. 4. The report owner (project manager) should ensure that the draft EFR assessment report is written in such a way as to meet the objectives set out in the business case. 5. The draft EFR assessment report should be checked to ensure that all data from the template has been included and passed to step E3. 1.The report owner (project manager) should designate appropriate individuals to provide quality assurance for the draft report. These could be members of ENISA staff or the EFR Stakeholder Forum, or subject matter experts. Preferably they would include a representative of the target Draft EFR audience Report owner Final version of assessment 2. The designated quality (project EFR assessment E3. QA report report [EF2.1]. assurors should read the draft manager). report {OE3.1] to Business case report to ensure clarity, accuracy Designated next step. [OB7.1]. and appropriateness to the target quality assurors. audience. 3. Quality assurors should determine if the stated objectives for the report have been achieved. 4. If there are issues with the report, these should be brought to the attention of the report owner (project manager) and corrections made where
  141. necessary. 5. The final version of the EFR assessment report should be passed to step E4. 1. The final version of the EFR assessment report should be passed to ENISA management for approval. 2. ENISA management should ENISA determine if the report requires management. Published report to be seen by the PSG, the E4. Obtain [OE4.1] to the EFR ENISA staff. Final report Management Board or other management knowledge PSG or version [OE3.1] stakeholders before publication. agreement . database [OA1.4] Management Also if any changes need to be and process F. Board if made for legal or other reasons. appropriate. 3. The final, approved report should be passed to Promotion, Dissemination and Feedback process, and stored in the EFR knowledge database [OA1.4].
  142. TABLE 5: ASSESSMENT REPORTING PROCESS DESCRIPTION
  143. 3.5.4 TECHNOLOGY AND TOOLS
  144. 3.6.2 PROCESS STEPS
  145. ENISA EFR Framework: Promotion, Dissemination and Feedback Process
  146. E. Assessment Reporting process
  147. EFR assessment Promotion plan report [OF4.1] template
  148. Key F1. Define channel promotion and data feedback plan
  149. Business case Promotion and [OB7.1] feedback plan F1. Make changes Plan OK? No [OF1.1] to plan
  150. F2. Determine promotion and Yes publication requirements
  151. External F2. Engage Yes resources? external promotion
  152. Launch plan [OF2.1]
  153. Launched EFR Promotion F3. Publication assessment report collateral [OF3.1] and launch [OF3.2]
  154. F4. Devise feedback and effectiveness capture
  155. Feedback F4. Obtain and templates [OF4.1] document feedback
  156. EFR Documented Knowledge feedback [OF4.2] database [OA1.4]
  157. G. Continuous Improvement process
  158. FIGURE 7: PROMOTION, DISSEMINATION AND FEEDBACK PROCESS FLOW DIAGRAM
  159. 3.6.3 PROCESS DESCRIPTION TABLE
  160. 1 An individual is designated as responsible for the promotion dissemination and feedback plan (either the report owner (project manager), or another member of the ENISA staff). 2. A promotion plan template is devised, including sections about: communications channels; launch plans and publicity; policy on ENISA staff. printed and downloaded versions Data about key Promotion, of the report; policy on extracts communication dissemination from the report; timing of launch; channels. and feedback F1. Define policy on gathering feedback; Business case owner. promotion objectives for success in take-up Promotion plan [OB7.1]. ENISA and feedback and effectiveness. [OF1.1] Promotion plan management. plan 3. The template is populated by the template PSG and promotion, dissemination and Management Final report feedback owner, using data from Board if version [OG4.1 the report itself and the business appropriate case and information about ENISA’s key communication channels. 4. The promotion plan is submitted to ENISA senior management for approval (senior management may consult the PSG or Management Board if appropriate). 5. Any changes to the plan, required by senior management (or the PSG or Management Board),
  161. are made.
  162. 6 The promotion plan is passed to
  163. step F2.
  164. 1 Using the promotion plan the
  165. promotion dissemination and
  166. feedback owner determines the
  167. resources required for launch of
  168. the report.
  169. 2 If external promotion resources
  170. are required, the promotion
  171. dissemination and feedback owner
  172. will be responsible for engaging Promotion these and ensuring the quality of dissemination their output. and feedback F2. Determine 3. The promotion dissemination Launch plan Promotion plan owner. launch and feedback owner ensures that [OF1.1] to next [OF1.1] External requirements all resources are in place and step. promotion available for the publication and resources (if launch of the report on the appropriate). designated launch date.
  173. 4 The promotion dissemination
  174. and feedback owner documents a
  175. plan with details of responsibilities
  176. and timing for the launch and
  177. publicity and communications
  178. surrounding it.
  179. 5 The launch plan is passed to step
  180. 1 The promotion dissemination
  181. and feedback owner ensures that Promotion all resources designated in the dissemination launch plan are aware of their roles Promotion and feedback F3. Launch and responsibilities in relation to collateral owner. EFR Launch plan the report’s launch and promotion. [OF3.1] and ENISA staff. assessment [OG1.1] 2. The promotion dissemination launched report External report and feedback owner ensures that [OF3.2] to next promotion the launch method and technology step resources (if (usually the ENISA website) is appropriate). appropriately sized to cope with
  182. the expected launch traffic.
  183. 3 The promotion dissemination and feedback owner ensures that all collateral (e.g.: printed versions of the report, abstracts, FAQs and publicity material) is available as required. 4. The promotion dissemination and feedback owner ensures that the report is launched as described in the plan, that all appropriate communication channels are used to notify interested parties of the launch, that collateral is distributed as required and that publicity events take place as planned. 5. Following launch, the report and collateral material are passed to step F4. 1. Templates are devised to gather feedback on the report and on the operation of the EFR Framework during report production. 2. As indicated in the business plan, mechanisms are agreed on Promotion Promotion methods of measuring uptake of dissemination collateral the report (e.g. number of Feedback and feedback [OF3.1]. downloads, number of citations in templates owner. F4. Feedback Launched other publications). [OF4.1]. Subject matter and report [OF3.2]. Documented 3. Promotion dissemination and experts. effectiveness Business case feedback feedback owner populates EFR Stakeholder [OB7.1] templates with data specific to the [OF4.2] to Forum. Feedback published assessment report and process G. Report readers templates. collateral and communicated to and users. appropriate recipients, as indicated in the business plan. 4. Promotion dissemination and feedback owner conducts interviews, to gather feedback, if appropriate, as indicated in the
  184. business plan. 5. Promotion dissemination and feedback owner gathers, analyses and documents data from uptake measurements, returned templates and interviews. 6.Documented, analysed data is stored in the EFR knowledge database and passed to the Continuous Improvement process.
  185. TABLE 6: PROMOTION, DISSEMINATION AND FEEDBACK PROCESS DESCRIPTION
  186. 3.6.4 TECHNOLOGY AND TOOLS
  187. 3.7.2 PROCESS STEPS
  188. ENISA EFR Framework: Continuous Improvement Process
  189. F. Promotion, Dissemination and Feedback process
  190. Documented feedback [OF4.2]
  191. Business case G1. Assess [OB7.1] feedback
  192. Feedback and effectiveness Change report [OG1.1] reports?
  193. G2. Change EFR No assessment reports
  194. Changed report Change templates [OG2.1] Framework?
  195. No G3. Change EFR Framework
  196. EFR Changed EFR A. Information Knowledge Framework G4. Follow-up Management processes [OG3.1] database activities process [OA1.4]
  197. Actions No required?
  198. Follow-up action plan [OG4.1]
  199. G4. Carry out actions
  200. Follow-up action reports [OG4.2]
  201. FIGURE 8: CONTINUOUS IMPROVEMENT PROCESS FLOW DIAGRAM
  202. 3.7.3 PROCESS DESCRIPTION TABLE
  203. 1 An individual is designated as
  204. being responsible for continuous
  205. improvement of the EFR
  206. Framework. This role requires
  207. continuous attention, rather than
  208. being active only during the
  209. production of an assessment
  210. report.
  211. 2 A template is devised for
  212. reporting feedback and Feedback report effectiveness of assessment [OG1.1] to reports to ENISA senior Continuous ENISA management and the PSG and Documented improvement management Management Board where feedback owner. and PSG and appropriate. [OF4.1]. Management ENISA G1. Assess 3. After an agreed interval Business case Board where management. feedback following publication of the report [OB7.1] appropriate, to PSG and (three months for example), the next step and to Feedback report Management continuous improvement owner the EFR template. Board where uses the analysed, documented knowledge appropriate. feedback and the business case to database write a report describing the [OA1.4].. positive and negative aspects of
  213. the feedback received and of the
  214. measurement of the report’s
  215. effectiveness.
  216. 4 If necessary, the report should
  217. contain recommendations for
  218. changes to report structure etc.
  219. and/or to Framework processes
  220. and for follow-up actions.
  221. 5 The report is passed to step G2.
  222. 1 The continuous improvement owner discusses with ENISA management recommended Changes to changes to the EFR assessment reporting report structure, launch or systems [OG2.1] Continuous G2. EFR promotion. to EFR improvement Assessment Feedback report 2. If necessary and appropriate, knowledge owner. report [OG1.1] resources are allocated to make database ENISA changes the identified and agreed changes. [OA1.4] and to management. 3. The changes are made and A. Information ENISA staff. information concerning them is fed Management back into the EFR knowledge process. database and thus into the Information Management process. 1. The continuous improvement owner discusses with ENISA management lessons learned Changes to EFR about the operation of the EFR Framework Framework processes Continuous processes recommended changes to these. improvement G3. EFR [OG3.1] to EFR Framework Feedback report 2. If necessary and appropriate, knowledge owner. process [OG1.1] resources are allocated to make database ENISA changes the identified and agreed changes. [OA1.4] and to management. A. Information 3. The changes are made and ENISA staff. Management information concerning them is fed process. back into the EFR knowledge database and thus into the Information Management process.
  223. 1 The continuous improvement owner discusses with ENISA management the requirement for follow-up actions (e.g. additional workshops or reports), the content and participants in these and their timing. 2. If appropriate, an individual is designated with responsibility for Follow-up plan carrying out the follow-up actions. [OG4.1] and Feedback report Continuous follow-up report 3. A follow-up plan template is [OG1.1]. improvement [OG4.2] to EFR devised containing fields G4. Follow-up Business case Knowledge owner. concerning follow-up reports, activities [OB7.1] database ENISA workshops, timing, participants etc. [OA1.4], and management. Follow-up plan 4. The designated individual process A: template. ENISA staff. populates the follow-up plan Information template with appropriate data Management. and agrees this with ENISA management. 5. The actions described in the plan are carried out. 6. Follow-up reports are documented and sent to the EFR knowledge database and A. Information Management process.
  224. TABLE 7: CONTINUOUS IMPROVEMENT PROCESS DESCRIPTION
  225. 3.7.4 TECHNOLOGY AND TOOLS