Difference between revisions of "Impact"

From CIPedia
Jump to navigation Jump to search
(Netherlands)
Line 2: Line 2:
  
 
==Definitions==
 
==Definitions==
=== European Definitions ===
+
=== [[EU|European Definitions]] ===
 
{{definition|Severity is the '''impact''' of the disruption or destruction of a particular infrastructure, with reference to (1) public effect (number of members of the population affected); (2) economic effect (significance of economic loss and/or degradation of products or services); (3) environmental effect; (4) political effects; (5) psychological effects; and (6) public health consequences. <ref>[http://eur-lex.europa.eu/LexUriServ/site/en/com%/2006/com2006_0787en01.pdf EC COM(2006) 787 final, Directive of the Council on the identification and designation of European Critical Infrastructure and the assessment of the need to improve their protection, EC, Brussels 12.12.2006]</ref>}}<br />
 
{{definition|Severity is the '''impact''' of the disruption or destruction of a particular infrastructure, with reference to (1) public effect (number of members of the population affected); (2) economic effect (significance of economic loss and/or degradation of products or services); (3) environmental effect; (4) political effects; (5) psychological effects; and (6) public health consequences. <ref>[http://eur-lex.europa.eu/LexUriServ/site/en/com%/2006/com2006_0787en01.pdf EC COM(2006) 787 final, Directive of the Council on the identification and designation of European Critical Infrastructure and the assessment of the need to improve their protection, EC, Brussels 12.12.2006]</ref>}}<br />
  
Line 10: Line 10:
  
 
=== National Definitions ===
 
=== National Definitions ===
==== Australia ====  
+
==== [[Australia]] ====  
 
{{definition|Impact is a sudden occurrence without prior warning. <ref name="MAIMAus">[https://www.em.gov.au/Documents/Manual03-AEMGlossary.PDF Australian Emergency Management Glossary, Emergency Management Australia (1998)]</ref>}}<br />
 
{{definition|Impact is a sudden occurrence without prior warning. <ref name="MAIMAus">[https://www.em.gov.au/Documents/Manual03-AEMGlossary.PDF Australian Emergency Management Glossary, Emergency Management Australia (1998)]</ref>}}<br />
==== Brazil ====
+
==== [[Brazil]] ====
 
{{definition|Impacto: mudança adversa no nível obtido dos objetivos do negócio. <ref>[http://www.biblioteca.presidencia.gov.br/publicacoes-oficiais-1/catalogo/orgao-essenciais/gabinete-de-seguranca-institucional/guia-de-referencia-para-seguranca-de-infraestruturas-criticas-da-informacao/at_download/file GUIA DE REFERÊNCIA PARA A SEGURANÇA DAS INFRAESTRUTURAS CRÍTICAS DA INFORMAÇÃO Versão 01 (Nov. 2010)/ ABNT NBR ISO/IEC 27005:2008: Tecnologia da Informação: Técnicas de Segurança: Gestão de Riscos de Segurança da Informação..]</ref><br />Impact is the adverse change in the achieved level of business objectives.}} <br />
 
{{definition|Impacto: mudança adversa no nível obtido dos objetivos do negócio. <ref>[http://www.biblioteca.presidencia.gov.br/publicacoes-oficiais-1/catalogo/orgao-essenciais/gabinete-de-seguranca-institucional/guia-de-referencia-para-seguranca-de-infraestruturas-criticas-da-informacao/at_download/file GUIA DE REFERÊNCIA PARA A SEGURANÇA DAS INFRAESTRUTURAS CRÍTICAS DA INFORMAÇÃO Versão 01 (Nov. 2010)/ ABNT NBR ISO/IEC 27005:2008: Tecnologia da Informação: Técnicas de Segurança: Gestão de Riscos de Segurança da Informação..]</ref><br />Impact is the adverse change in the achieved level of business objectives.}} <br />
 +
==== [[Czech Republic]] ====
 +
{{definition| (1) Nepříznivá změna dosaženého stupně cílů. (2) Následky určitého činu nebo události. <ref> http://www.govcert.cz/download/nodeid-561  Výkladový slovník kybernetické bezpečnosti (2013)</ref> <br/><br/>(1) Adverse change in the attained degree of objectives. (2) Consequenses of a certain act or event. <ref> http://www.govcert.cz/download/nodeid-561  Výkladový slovník kybernetické bezpečnosti (2013)</ref>}}<br/>
  
==== France ====
+
==== [[France]] ====
 
{{definition|(Unofficial translation) Predictable effects of a successful attack on a target. They are estimated in terms of activities’ degradation for the country or of riskiness for the population.}}
 
{{definition|(Unofficial translation) Predictable effects of a successful attack on a target. They are estimated in terms of activities’ degradation for the country or of riskiness for the population.}}
 
<big>The French original version is:</big>
 
<big>The French original version is:</big>
Line 21: Line 23:
 
<br />
 
<br />
  
==== Netherlands ====
+
==== [[Netherlands]] ====
 
{{definition|Impact is defined as the consequences of a threat which occurs.<br/><br/>Impact is gedefinieerd als de gevolgen van een bedreiging die zich manifesteert. <ref>[http://www.pblq.nl/media/63123/HEC%20Zakboekje%20preventie%20cybercrime.pdf Zakboekje Preventie Cybercrime (2008]</ref>}}<br />
 
{{definition|Impact is defined as the consequences of a threat which occurs.<br/><br/>Impact is gedefinieerd als de gevolgen van een bedreiging die zich manifesteert. <ref>[http://www.pblq.nl/media/63123/HEC%20Zakboekje%20preventie%20cybercrime.pdf Zakboekje Preventie Cybercrime (2008]</ref>}}<br />
 
<big>As part of the Methodology for National Risk Assessment (Dutch: NRB-methodiek), the Netherlands has defined a set of impact assessment criteria:
 
<big>As part of the Methodology for National Risk Assessment (Dutch: NRB-methodiek), the Netherlands has defined a set of impact assessment criteria:
Line 41: Line 43:
 
</big>
 
</big>
  
==== United Kingdom (UK) ====
+
==== [[United Kingdom|United Kingdom (UK)]] ====
 
{{definition|Impact is the scale of the [[consequence|consequences]] of a [[hazard]] or [[threat]] expressed in terms of a reduction in human welfare, [[damage]] to the environment and loss of security. <ref> [https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/61046/EP_Glossary_amends_18042012_0.pdf Glossary - Revision to Emergency Preparedness, Cabinet Office (2012)]</ref>}}  
 
{{definition|Impact is the scale of the [[consequence|consequences]] of a [[hazard]] or [[threat]] expressed in terms of a reduction in human welfare, [[damage]] to the environment and loss of security. <ref> [https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/61046/EP_Glossary_amends_18042012_0.pdf Glossary - Revision to Emergency Preparedness, Cabinet Office (2012)]</ref>}}  
 
For the approach of the UK regarding impact assessment, refer to [[Criticality Scale]].<br />
 
For the approach of the UK regarding impact assessment, refer to [[Criticality Scale]].<br />
  
 
=== Standard Definitions ===
 
=== Standard Definitions ===
==== ISO/IEC 27000:2014 ====
+
==== [[ISO|ISO/IEC 27000:2014]] ====
 
{{definition|Adverse change to the level of business objectives achieved. <ref name="ISO27000-14"> [http://www.iso.org/iso/home/store/catalogue_ics/catalogue_detail_ics.htm?csnumber=63411 ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary]</ref>}}
 
{{definition|Adverse change to the level of business objectives achieved. <ref name="ISO27000-14"> [http://www.iso.org/iso/home/store/catalogue_ics/catalogue_detail_ics.htm?csnumber=63411 ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary]</ref>}}
==== ISO/PAS 22399:2007 ====
+
==== [[ISP|ISO/PAS 22399:2007]] ====
 
{{definition|evaluated consequence of a particular outcome. <ref name ="ISO PAS 22399:2007">  ISO PAS 22399:2007: Societal security – Guideline for incident preparedness and operational continuity management, ISO, Geneva, Switzerland, 2007/2011</ref>}}
 
{{definition|evaluated consequence of a particular outcome. <ref name ="ISO PAS 22399:2007">  ISO PAS 22399:2007: Societal security – Guideline for incident preparedness and operational continuity management, ISO, Geneva, Switzerland, 2007/2011</ref>}}
 
<br />
 
<br />
 
===Other definitions===
 
===Other definitions===
==== Ontario (Canada) ====
+
==== [[Ontario]] ([[Canada]]) ====
 
{{definition|Impact is the negative effect of a hazardous incident on people, property, the environment, the economy and/or services.<br/><br/>Impact: répercussion négative d’un incident dangereux sur les personnes, les biens, l’environnement, l'économie ou les services. <ref name="Can"> [http://www.sse.gov.on.ca/mgs/onterm/Documents/Glossaries/EMO%20Glossary%20EN-FR.htm Ontario English-French Emergency Management Glossary of Terms (2011)]</ref>}}<br /><br />
 
{{definition|Impact is the negative effect of a hazardous incident on people, property, the environment, the economy and/or services.<br/><br/>Impact: répercussion négative d’un incident dangereux sur les personnes, les biens, l’environnement, l'économie ou les services. <ref name="Can"> [http://www.sse.gov.on.ca/mgs/onterm/Documents/Glossaries/EMO%20Glossary%20EN-FR.htm Ontario English-French Emergency Management Glossary of Terms (2011)]</ref>}}<br /><br />
  
Line 69: Line 71:
 
[[Category:Consequence]]
 
[[Category:Consequence]]
 
[[Category:Risk]]
 
[[Category:Risk]]
{{#set:defined by=EU|defined by=Australia|defined by=Brazil|defined by=France|defined by=Netherlands|defined by=United Kingdom|defined by=ISO|defined by=Ontario}}
+
{{#set:defined by=EU|defined by=Australia|defined by=Brazildefined by=Czech Republic||defined by=France|defined by=Netherlands|defined by=United Kingdom|defined by=ISO|defined by=Ontario}}

Revision as of 17:19, 18 July 2015

The term is strongly related to the term "Consequence" and further work is needed in order to distinguish between the two terms. The term Severity is also used as a synonym.

Definitions

European Definitions

Severity is the impact of the disruption or destruction of a particular infrastructure, with reference to (1) public effect (number of members of the population affected); (2) economic effect (significance of economic loss and/or degradation of products or services); (3) environmental effect; (4) political effects; (5) psychological effects; and (6) public health consequences. [1]


The strong and noticeable effect or influence on something or someone. In the context with CBRN often used to describe the effect of a CBRN release. [2]

Other International Definitions

National Definitions

Australia

Impact is a sudden occurrence without prior warning. [3]


Brazil

Impacto: mudança adversa no nível obtido dos objetivos do negócio. [4]
Impact is the adverse change in the achieved level of business objectives.


Czech Republic

(1) Nepříznivá změna dosaženého stupně cílů. (2) Následky určitého činu nebo události. [5]

(1) Adverse change in the attained degree of objectives. (2) Consequenses of a certain act or event. [6]


France

(Unofficial translation) Predictable effects of a successful attack on a target. They are estimated in terms of activities’ degradation for the country or of riskiness for the population.

The French original version is:

Impacts (ou conséquences dommageables): effets prévisibles d’une agression réussie sur une cible, estimés en termes d’atteinte aux activités du pays ou de danger pour la population. [7]


Netherlands

Impact is defined as the consequences of a threat which occurs.

Impact is gedefinieerd als de gevolgen van een bedreiging die zich manifesteert. [8]


As part of the Methodology for National Risk Assessment (Dutch: NRB-methodiek), the Netherlands has defined a set of impact assessment criteria:

1. Territorial Security:
1.1 - infringement of the integrity of the Dutch territory;
1.2 - infringement of the integrity of the international position of The Netherlands
2. Physical Security:
2.1 - casualties;
2.2 - seriously wounded and chronically ill people;
2.3 - suffering of people (lack of primary supplies such as drinking water, food, medicine)
3. Economic Security:
3.1 - costs
4. Ecological Safety:
4.1 - long duration infringement of the environment and nature (flora and fauna)
5. Social and Cultural stability:
5.1 - disrupted daily life;
5.2 - infringement of the democratic constitutional state;
5.3 - social-psychological impact

United Kingdom (UK)

Impact is the scale of the consequences of a hazard or threat expressed in terms of a reduction in human welfare, damage to the environment and loss of security. [9]

For the approach of the UK regarding impact assessment, refer to Criticality Scale.

Standard Definitions

ISO/IEC 27000:2014

Adverse change to the level of business objectives achieved. [10]

ISO/PAS 22399:2007

evaluated consequence of a particular outcome. [11]


Other definitions

Ontario (Canada)

Impact is the negative effect of a hazardous incident on people, property, the environment, the economy and/or services.

Impact: répercussion négative d’un incident dangereux sur les personnes, les biens, l’environnement, l'économie ou les services. [12]



See also

Notes

  1. EC COM(2006) 787 final, Directive of the Council on the identification and designation of European Critical Infrastructure and the assessment of the need to improve their protection, EC, Brussels 12.12.2006
  2. European Commission's CBRN Glossary, 2012
  3. Australian Emergency Management Glossary, Emergency Management Australia (1998)
  4. GUIA DE REFERÊNCIA PARA A SEGURANÇA DAS INFRAESTRUTURAS CRÍTICAS DA INFORMAÇÃO Versão 01 (Nov. 2010)/ ABNT NBR ISO/IEC 27005:2008: Tecnologia da Informação: Técnicas de Segurança: Gestão de Riscos de Segurança da Informação..
  5. http://www.govcert.cz/download/nodeid-561 Výkladový slovník kybernetické bezpečnosti (2013)
  6. http://www.govcert.cz/download/nodeid-561 Výkladový slovník kybernetické bezpečnosti (2013)
  7. INSTRUCTION GENERALE INTERMINISTERIELLE RELATIVE A LA SECURITE DES ACTIVITES D’IMPORTANCE VITALE N°6600/SGDSN/PSE/PSN du 7 janvier 2014, PREMIER MINISTRE, SECRETARIAT GENERAL DE LA DEFENSE ET DE LA SECURITE NATIONALE, Direction Protection et Sécurité de l’Etat N° NOR: PRMD1400503J
  8. Zakboekje Preventie Cybercrime (2008
  9. Glossary - Revision to Emergency Preparedness, Cabinet Office (2012)
  10. ISO/IEC 27000:2014, Information technology -- Security techniques -- Information security management systems -- Overview and vocabulary
  11. ISO PAS 22399:2007: Societal security – Guideline for incident preparedness and operational continuity management, ISO, Geneva, Switzerland, 2007/2011
  12. Ontario English-French Emergency Management Glossary of Terms (2011)