Posts

Nothing Found

Sorry, no posts matched your criteria

Interviews

Nothing Found

Sorry, no posts matched your criteria

CORE-Observatory

Comentario de La Brecha en Infraestructura Crítica: Instalaciones Portuarias en Estados Unidos y Vulnerabilidades Cibernéticas, Documento de Política, Center for 21st Century Security and Intelligence (CORE1095)

Resumen: En un documento de política de 50 páginas del Brookings Institute y elaborado por el Comandante Joseph Kramek de la Guardia Costera de los Estados Unidos y Miembro Ejecutivo Federal en la institución, se discute el estado actual de los asuntos relacionados con las vulnerabilidades en los puertos estadounidenses y se presentan las opciones para reforzar la seguridad cibernética. En el resumen ejecutivo, el Comandante Kramek escribe que las instalaciones portuarias estadounidenses de hoy en día se basan tanto de las redes y sistemas informáticos y de control como se basan de los estibadores para asegurar el flujo de comercio marítimo del que dependen el Estado, la economía y la seguridad nacional. Sin embargo, a diferencia de otros sectores críticos en la infraestructura, se ha prestado poca atención a los sistemas de redes que sustentan las operaciones portuarias. Reporte disponible (en inglés) en: http://www.brookings.edu/~/media/research/files/papers/2013/07/02%20cyber%20port%20security%20kramek/03%20cyber%20port%20security%20kramek.pdf

[s2If is_user_logged_in()]

Full review: No cybersecurity standards have been promulgated for U.S. ports, nor has the U.S. Coast Guard, the lead federal agency for maritime security, been granted cybersecurity authorities to regulate ports or other areas of maritime critical infrastructure. In the midst of this lacuna of authority is a sobering fact: according to the most recent National Intelligence Estimate (NIE) the next terrorist attack on U.S. Critical Infrastructure and Key Resources (CIKR) is just as likely to be a cyber attack as a kinetic attack.

The potential consequences of even a minimal disruption of the flow of goods in U.S. ports would be high. The zero-inventory, just-in-time delivery system that sustains the flow of U.S. commerce would grind to a halt in a matter of days; shelves at grocery stores and gas tanks at service stations would run empty. In certain ports, a cyber disruption affecting energy supplies would likely send not just a ripple but a shockwave through the U.S. and even global economy.

Given the absence of standards and authorities, this paper explores the current state of cybersecurity awareness and culture in selected U.S. port facilities. The use of the post-9/11 Port Security Grant Program (PSGP), administered by the Federal Emergency Management Agency, is also examined to see whether these monies are being used to fund cybersecurity projects.

Full citation:   The Critical Infrastructure Gap: U.S. Port Facilities and Cyber Vulnerabilities, Policy Paper, July 2013, Center for 21st Century Security and Intelligence.

CORE1095

Keywords: Maritime Security, Cyber-security, Port Security Grant Program (PSGP), Port facility, Coast Guard, Maritime Transportation Security Act (MTSA).

[/s2If]

Introducción a la Gestión de la Cadena de Suministro (Capítulo 2 Compendio CASSANDRA, CORE2007a)

Resumen

El segundo capítulo del Compendio CASSANDRA brinda una visión general sobre la teoría y práctica de la gestión moderna de la cadena de suministro. Escrito en un lenguaje común, el texto explica una amplia gama de estrategias para la gestión de cadenas de suministro, desde la gestión eficiente a la logística ágil y de rápida reacción. El capítulo también define terminología fundamental de cadena de suministro y discute las tendencias actuales en la logística, incluyendo la “sincro-modalidad”, el uso de los proveedores de servicios logísticos “4PL” (fourth-party logistics) y la logística verde. El capítulo presenta varios marcos de referencia de la cadena de suministro que ilustran una serie de actividades interdependientes y actores de interés involucrados en el transporte internacional de carga. El compendio CASSANDRA está disponible en(disponible solo en inglés).

Revisión por Toni Männistö (CBRA).

[s2If is_user_logged_in()]

Full review

The compendium summarizes the SCOR and UN/CEFACT supply chain models, that may be the two most used logistics reference frameworks in the world. The document also discusses less known academic conceptual models that seek to simplify the complexity of supply chain management by categorizing and explaining management strategies, activities, stakeholders and their roles and responsibilities. The section on the future trends in logistics offers a great outlook on the most likely changes and driving forces in the logistics industry. The outlook suggests that for example synchromodality (increased flexibility in transport mode selection), green logistics (less emissions), use of 4PL logistics service providers (outsourced supply chain management), and continuously increasing ship and port sizes will reshape the cross-border logistics over the years. The document also explains key CASSANDRA concepts and their impacts on international supply chain management. For instance, the Data Pipeline, a pivotal CASSANDRA concept, seeks to enhance sharing of information across supply chain stakeholders, in particularly from business operators to customs and other border control authorities. Most importantly, the Data Pipeline would allow customs officers to access commercial information, that normally is exchanged only between buyers and sellers, early in the upstream supply chain at the consignment completion point (CCP). This accurate, early commercial information would enable the customs and other border control agencies to assess security and other risks of cargo early on.

All in all, the document provides a crash refresher course on basic and advanced logistics terminology that would be beneficial for many the CORE consortium, especially for those partners whose expertise is mainly outside the logistics industry. The CORE demonstrators benefit from descriptions of CASSANDRA innovations that support information exchange and improve visibility across the supply chain. The demos might choose to reuse some of these CASSANDRA innovations or their components. The CASSANDRA compendium also contains a great deal of material that could be reused for education and training purposes in CORE (WP19). Finally, the chapter concludes with recommendations that are relevant also for CORE. The chapter recommends, for example, that because of broad variety of international supply chains, CASSANDRA solutions should be adaptable for different contexts.

Reference

Hintsa, J. and Uronen, K. (Eds.) (2012), “Common assessment and analysis of risk in global supply chains “, Compendium of FP7-project CASSANDRA, Chapter 2

CORE2007

[/s2If]

Trade and money laundering uncontained (the Economist, May 2014, CORE2006)

Summary

International trade is becoming one of the main instruments for cross-border money laundering aside common bank transfers, remittances and cash smuggling. The ”trade-based money laundering” disguises illegal trading as seemingly legitimate commercial transactions. The most common technique is mis-invoicing in which fraudsters undervalue imports or overvalue exports to repatriate ill-gotten money from abroad. For example, official records show that Mexican exports to US are much higher than the US imports from Mexico, a discrepancy that signs fraud by Mexican criminals, most likely drug cartels. In general, the trade-based money laundering offers new financial tools for a broad range of drug traffickers, arms smugglers, corrupt politicians, terrorists and evaders of taxes, duties and capital controls. Review by Toni Männistö (CBRA)

[s2If is_user_logged_in()]

Full review

International trade is becoming one of the main instruments for cross-border money laundering aside common bank transfers, remittances and cash smuggling. The ”trade-based money laundering” disguises illegal trading as seemingly legitimate commercial transactions. The most common technique is mis-invoicing in which fraudsters undervalue imports or overvalue exports to repatriate ill-gotten money from abroad. For example, official records show that Mexican exports to US are much higher than the US imports from Mexico, a discrepancy that signs fraud by Mexican criminals, most likely drug cartels. In general, the trade-based money laundering offers new financial tools for a broad range of drug traffickers, arms smugglers, corrupt politicians, terrorists and evaders of taxes, duties and capital controls.

The new methods for cross-border money laundering and tax evasion concern most CORE demonstrations, especially those involving international cargo movements. The emerging risk of trade-based money laundering calls for new and more effective enforcement of trade transactions. CORE is developing new solutions (e.g., data pipeline and system-based supervision) for capturing and sharing trade information across logistics operators and law enforcement agencies. The new solutions likely improve law enforcement’s capability to detect suspicious trade transactions that may have something to do with the trade-based money laundering. However, building such capability requires IT integration (e.g., interoperability), risk awareness and education and training. CORE consortium addresses these complementary activities in work carried out in risk, IT and educational clusters.

Reference

Trade and money laundering uncontained, the Economist, May 3rd 2014

CORE2006

[/s2If]

Review of COMMISSION IMPLEMENTING REGULATION (EU) No 889/2014 of 14 August 2014 amending Regulation (EEC) No 2454/93, as regards recognition of the common security requirements under the regulated agent and known consignor programme and the Authorised Economic Operator programme (CORE1069)

Summary: Existing customs Regulation ((EEC) No 2913/92 establishing the Community Customs Code) and aviation legislation (Regulation (EC) No 300/2008) provides for certain recognition of the certifications under the respective programmes, in particular with regard to the security examinations done for each of them. Regulation (EU) No 889/2014 is necessary for the recognition of the known consignor status with its relevance for the AEO as well, frame the scope of recognition of the common requirements between the respective programmes and allow for the necessary exchange of information between customs and aviation authorities. Original files are coded as CORE1069, available in the CORE e-library. Source file at: http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32014R0889&from=EN
Read more

Comentario en el proyecto FP7 IMCOSEC (CORE3001)

Resumen: Este es un comentario de los proyectos de referencia/resultados reutilizables, en el proyecto FP7 IMCOSEC. La investigación en IMCOSEC (Enfoque integrado para mejorar la cadena de suministro para el transporte de contenedores y la seguridad integrada al mismo tiempo) estaba en conflicto con las siguientes dos tendencias en los años antes de que empezara el proyecto: la eliminación de las barreras comerciales para asegurar el libre comercio, y el aumento de las demandas de seguridad para contrarrestar la amenaza del terrorismo, principalmente. El autor de la revisión es Marcus Engler, ISL. El documento original se encuentra en la biblioteca electrónica deCORE codificada como CORE3001. Más información sobre el proyecto en: http://cordis.europa.eu/search/result_en?q=IMCOSEC
Read more

ACC3 regulación en la UE (CORE1000)

Resumen: Este comentario es acerca de la regulación de validación de seguridad de aviación en la UE. ACC3 se refiere al operador de Carga Aérea (o correo) que opera en un tercer país en Europa, con el objetivo de proporcionar un enfoque holístico a las amenazas de tales carga de entrada. Esta revisión puede ser beneficioso para la grupo demo del CORE, incluyendo WP12, WP15 y WP17. El análisis (con el método de 8 pasos) se presenta en su totalidad en el documento CORE1000. http://ec.europa.eu/transport/modes/air/security/doc/eu_rules_on_aviation_security.pdf

Read more