"A risk assessment of the Piql Services" by FFI

weapon system on a specific party, the general having of the weapon system can increase the state’s influence generally on the world stage. It can also lead to increased authority in a bilateral relationship more specifically. The knowledge gained from the acquiring of the piqlFilm can be used directly to force certain behaviour, or indirectly when the counterparts’ knowledge of you having the information is enough to give them an elevated position, even when they do not intend to make practical use of the information you have. Market power is understood here as a more abstract notion than the financial reward to be had from economic gain. Market power is gained when an entity’s standing in the market is increased, or its reputation in improved, without this being directly connected to an increase in profit. An example may be if an entity gets access to innovative technology. When a threat actor acts due to motivation of economic gain , he or she does so because they imagine there is a financial reward to be had in acquiring an object – in this case, the information on the piqlFilm. The economic gain can be direct, meaning that usage of the object may result in direct potentially long-term profit, or it can be indirect, meaning that the object can be sold to a third party for a short-term profit. If a threat actor seeks to gain possession of an object solely to appease his or her own wishes, they act out of idiosyncratic interest . 47 Such interests can be the destruction of the film for destruction’s sake, perhaps governed by a wish for revenge. The method parameter describes the actions a threat actor would take to achieve their goals. The methods vary regarding how demanding they are to implement, and thus represent different levels of ambition and capacity [39 p.13]. The relevant values assigned here are physical destruction, physical manipulation, logical destruction, logical manipulation and insider. With regards to method, it is distinguished between physical and logical attacks on the assets in question, as well as employing the method of engaging an insider to do the job. As the Piql Preservation Services is both an online and offline medium during different phases in the service journey, it is subject to threats and hazards of both a logical [56 p.18] and physical nature: by logical threats or hazards we mean threats faced by the Piql Preservation Services while the information is stored or transferred electronically; by physical threats and hazards we mean all that may harm the physical infrastructure of the Piql Preservation Services, including its components and their critical dependencies. Within the separation between physical and logical we also distinguish between destruction and manipulation, as both types of attacks can result in the irreparable damage of the information or the subtle altering of the information. Physical destruction entails damaging the medium containing the information, i.e. after the information has been transferred to the film, beyond repair. It also entails the destruction of other objects and materials that make up the Piql Preservation Services, such as the machines required to develop the piqlFilm, or the finer electronics of the piqlVault system. Additionally,

47 According to The Concise Oxford English Dictionary [44], idiosyncrasy is defined as a mode of behaviour or way of thought specific to an individual.

100

FFI-RAPPORT 16/00707

Made with FlippingBook Online newsletter