and collection in cooperation with organizations. Or-
ganizations establish SA on a technical and organi-
zational level. At national level, this information is
processed and analyzed in order to support national
decision makers. In this paper, we proposed a CSA
model for NCSCs for SA gaining and decision mak-
ing in the event of large-scale cyber incidents with
various escalation levels. This modern CSA model
can manage cyber security incidents with prevention:
using a common information-sharing environment al-
lows the early detection of sophisticated attacks, or
even large-scale cyber campaigns against the national
critical infrastructures. To demonstrate our approach,
we illustrated an information sharing scenario based
on a past nation-state attack against the CIs.
For future work, we aim to further develop and in-
vestigate the CSA model for NCSCs focusing on legal
aspects and examining the impact of international co-
operations.
ACKNOWLEDGEMENTS
This study was partly funded by the Austrian FFG re-
search program KIRAS in course of the project CISA
(850199).
REFERENCES
Artman, H. (2000). Team situation assessment and infor-
mation distribution. Ergonomics, 43(8):1111–1128.
Biernacki, P. and Waldorf, D. (1981). Snowball sampling:
Problems and techniques of chain referral sampling.
Sociological methods & research, 10(2):141–163.
Boyd, J. R. (1996). The essence of winning and losing.
Unpublished lecture notes.
Brehmer, B. (2005). The dynamic ooda loop: Amalgamat-
ing boyds ooda loop and the cybernetic approach to
command and control. In International command and
control research technology symposium, pages 365–
368.
Conti, G., Nelson, J., and Raymond, D. (2013). Towards
a cyber common operating picture. In Cyber Con-
flict (CyCon), 2013 5th International Conference on,
pages 1–17. IEEE.
Endsley, M. R. (1988). Situation awareness global assess-
ment technique (sagat). In Aerospace and Electronics
Conference, pages 789–795. IEEE.
Endsley, M. R. (1995). Toward a theory of situation aware-
ness in dynamic systems. Human Factors: The Jour-
nal of the Human Factors and Ergonomics Society,
37(1):32–64.
European Parliament (2015). The directive on security of
network and information systems (nis directive).
Evancich, N., Lu, Z., Li, J., Cheng, Y., Tuttle, J., and Xie, P.
(2014). Network-wide awareness. In Cyber Defense
and Situational Awareness, pages 63–91. Springer.
Franke, U. and Brynielsson, J. (2014). Cyber situational
awareness A systematic review of the literature. Com-
puters & Security, 46:18–31.
GovCERT.ch (2016). APT Case RUAG.
https://www.melani.admin.ch/dam/melani/en/
dokumente/2016/technical [Online; accessed 16-
July-2016].
ICS-CERT (2016-02-25). Cyber-attack against ukrainian
critical infrastructure (dhs). https://ics-cert.us-
cert.gov/alerts/IR-ALERT-H-16-056-01. Accessed:
2016-04-25.
Kaber, D. B. and Endsley, M. R. (2004). The effects of level
of automation and adaptive automation on human per-
formance, situation awareness and workload in a dy-
namic control task. Theoretical Issues in Ergonomics
Science, 5(2):113–153.
Kaempf, G. L., Wolf, S., and Miller, T. E. (1993). De-
cision making in the aegis combat information cen-
ter. In Proceedings of the Human Factors and Er-
gonomics Society Annual Meeting, volume 37, pages
1107–1111. SAGE Publications.
Luiijf, E., Besseling, K., and De Graaf, P. (2013). Nine-
teen national cyber security strategies. Int’l Journal of
Critical Infrastructures 6, 9(1-2):3–31.
Okolica, J., McDonald, J. T., Peterson, G. L., Mills, R. F.,
and Haas, M. W. (2009). Developing systems for
cyber situational awareness. In 2nd Cyberspace Re-
search Workshop, page 46.
Onwubiko, C. (2012). Situational Awareness in Computer
Network Defense: Principles, Methods and Applica-
tions: Principles, Methods and Applications. IGI
Global.
Raulerson, E. L. (2013). Modeling cyber situational aware-
ness through data fusion. Technical report, DTIC Doc-
ument.
SANS-ICS (2016-03-18). Analysis of the
cyber attack on the ukrainian power
grid. https://ics.sans.org/media/E-
ISAC SANS Ukraine DUC 5.pdf. Accessed:
2016-04-25.
Steinberg, A., Bowman, C., and White, F. (1998). Revisions
to the JDL Model. In Joint NATO/IRIS Conference
Proceedings, Quebec, October.
Tadda, G. P. and Salerno, J. S. (2010). Overview of cyber
situation awareness. In Cyber Situational Awareness,
number 46 in Advances in Information Security, pages
15–35. Springer US.
White, A. (1987). Data fusion lexicon, joint directors of
laboratories, technical panel for c3. Naval Ocean Sys-
tems Center, San Diego, Tech. Rep.
Analysis and Assessment of Situational Awareness Models for National Cyber Security Centers
345