Can Sweden handle a cyber attack ? Documentation from an exercise
Publish date: 2002-01-01
Report number: FOI-R--0635--SE
Pages: 78
Written in: Swedish
Abstract
This report is about a gaming-based exercise that was performed for midd le and to some extent top management in the Swedish Govemment Office in the spring of 2002. The Government Office is the entity that supports the Cabinet ministers in their policymaking and oversight of the independent agencies that make up the Swedish national government. The exercise was performed according to a modified The Day After format. The report deals with both method and content. According to the chosen format, the scenario material consists of a Future History leading up to the progressively more dramatic story told in Steps 1 and 2. For Step 1 we used a prepared Decision Memo according to the standard version of The Day After methodology. In Step 2 instead we used a structured brainstorming format under very tight time constraints. Also in Step 3, where the players are invited to take advantage of the crisis management experience gained in Steps 1 and 2 to discuss present strategic choices, we utilised structured brainstorming. Both with regard to methodology and the scenario material the exercise was successful. The scenario material has also proven to be of value in other contexts. Thus, results from another Swedish exercise on IT related security issues - organised by the Swedish Armed Forces with top people from several other agencies participating - are also presented in the report. Notably this exercise treated real-time crises management extensively, a theme that the Government Office managers dealt with in less explicit terms.