<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Chris McPhee</style></author><author><style face="normal" font="default" size="100%">Dan Craigen</style></author><author><style face="normal" font="default" size="100%">Steven Muegge</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Editorial: Critical Infrastructures and Cybersecurity (June 2015)</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">botnet</style></keyword><keyword><style  face="normal" font="default" size="100%">club theory</style></keyword><keyword><style  face="normal" font="default" size="100%">critical infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">design principles</style></keyword><keyword><style  face="normal" font="default" size="100%">design science</style></keyword><keyword><style  face="normal" font="default" size="100%">healthcare</style></keyword><keyword><style  face="normal" font="default" size="100%">networked medical devices</style></keyword><keyword><style  face="normal" font="default" size="100%">project management maturity model</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2015</style></year><pub-dates><date><style  face="normal" font="default" size="100%">06/2015</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">http://timreview.ca/article/901</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">5</style></volume><pages><style face="normal" font="default" size="100%">3-5</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><issue><style face="normal" font="default" size="100%">6</style></issue><custom1><style face="normal" font="default" size="100%">Technology Innovation Management Review
Chris McPhee is Editor-in-Chief of the &lt;em&gt;Technology Innovation Management Review&lt;/em&gt;. Chris holds an MASc degree in Technology Innovation Management from Carleton University in Ottawa, Canada, and BScH and MSc degrees in Biology from Queen's University in Kingston, Canada. He has over 15 years of management, design, and content-development experience in Canada and Scotland, primarily in the science, health, and education sectors. As an advisor and editor, he helps entrepreneurs, executives, and researchers develop and express their ideas.</style></custom1><custom2><style face="normal" font="default" size="100%">Communications Security Establishment
Dan Craigen is a Science Advisor at the Communications Security Establishment in Canada and a Visiting Scholar at the Technology Innovation Management Program of Carleton University in Ottawa, Canada. Previously, he was President of ORA Canada, a company that focused on High Assurance/Formal Methods and distributed its technology to over 60 countries. His research interests include formal methods, the science of cybersecurity, and technology transfer. He was the chair of two NATO research task groups pertaining to validation, verification, and certification of embedded systems and high-assurance technologies. He received his BScH and MSc degrees in Mathematics from Carleton University.</style></custom2><custom3><style face="normal" font="default" size="100%">Carleton University
Steven Muegge is an Assistant Professor at the Sprott School of Business at Carleton University in Ottawa, Canada, where he teaches and leads a research program within Carleton’s Technology Innovation Management (TIM) program. His research, teaching, and community service interests include technology entrepreneurship and commercialization, non-traditional settings for innovation and entrepreneurship (business ecosystems, communities, platforms, and interconnected systems that combine these elements), and business models of technology entrepreneurs (especially in non-traditional settings).</style></custom3></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Chris McPhee</style></author><author><style face="normal" font="default" size="100%">Tony Bailetti</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Editorial: Cybersecurity (January 2015)</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">automotive manufacturing</style></keyword><keyword><style  face="normal" font="default" size="100%">botnet takedowns</style></keyword><keyword><style  face="normal" font="default" size="100%">botnets</style></keyword><keyword><style  face="normal" font="default" size="100%">commercialization</style></keyword><keyword><style  face="normal" font="default" size="100%">critical infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber-attacks</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">employee training</style></keyword><keyword><style  face="normal" font="default" size="100%">gamification</style></keyword><keyword><style  face="normal" font="default" size="100%">Internet</style></keyword><keyword><style  face="normal" font="default" size="100%">outsourcing</style></keyword><keyword><style  face="normal" font="default" size="100%">quantum key distribution</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2015</style></year><pub-dates><date><style  face="normal" font="default" size="100%">01/2015</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">http://timreview.ca/article/860</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">5</style></volume><pages><style face="normal" font="default" size="100%">3-4</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><issue><style face="normal" font="default" size="100%">1</style></issue><custom1><style face="normal" font="default" size="100%">Technology Innovation Management Review
Chris McPhee is Editor-in-Chief of the &lt;em&gt;Technology Innovation Management Review&lt;/em&gt;. Chris holds an MASc degree in Technology Innovation Management from Carleton University in Ottawa and BScH and MSc degrees in Biology from Queen's University in Kingston. He has over 15 years of management, design, and content-development experience in Canada and Scotland, primarily in the science, health, and education sectors. As an advisor and editor, he helps entrepreneurs, executives, and researchers develop and express their ideas.</style></custom1><custom2><style face="normal" font="default" size="100%">Carleton University
Tony Bailetti is an Associate Professor in the Sprott School of Business and the Department of Systems and Computer Engineering at Carleton University, Ottawa, Canada. Professor Bailetti is the Director of Carleton University's Technology Innovation Management (TIM) program. His research, teaching, and community contributions support technology entrepreneurship, regional economic development, and international co-innovation.</style></custom2></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Walter Miron</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Q&amp;A. Should the Internet Be Considered Critical Infrastructure?</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">communication networks</style></keyword><keyword><style  face="normal" font="default" size="100%">critical infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber-attacks</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">information technology</style></keyword><keyword><style  face="normal" font="default" size="100%">Internet</style></keyword><keyword><style  face="normal" font="default" size="100%">vulnerabilities</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2015</style></year><pub-dates><date><style  face="normal" font="default" size="100%">01/2015</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">http://timreview.ca/article/865</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">5</style></volume><pages><style face="normal" font="default" size="100%">37-40</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><issue><style face="normal" font="default" size="100%">1</style></issue><custom1><style face="normal" font="default" size="100%">TELUS Communications
Walter Miron is a Director of Technology Strategy at TELUS Communications, where he is responsible for the evolution of their packet and optical networks. He has over 20 years of experience in enterprise and service provider networking conducting technology selection and service development projects. Walter is a member of the research program committee of the SAVI project, the Heavy Reading Global Ethernet Executive Council, and the ATOPs SDN/nFV Working Group. He is also the Chair of the Venus Cybersecurity Corporation and is a graduate student in the Technology Innovation Management (TIM) program at Carleton University in Ottawa, Canada.</style></custom1></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Walter Miron</style></author><author><style face="normal" font="default" size="100%">Kevin Muita</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Cybersecurity Capability Maturity Models for Providers of Critical Infrastructure</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">adoption</style></keyword><keyword><style  face="normal" font="default" size="100%">bersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">capability maturity models</style></keyword><keyword><style  face="normal" font="default" size="100%">compliance</style></keyword><keyword><style  face="normal" font="default" size="100%">critical infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">framework</style></keyword><keyword><style  face="normal" font="default" size="100%">municipalities</style></keyword><keyword><style  face="normal" font="default" size="100%">protection</style></keyword><keyword><style  face="normal" font="default" size="100%">regulation</style></keyword><keyword><style  face="normal" font="default" size="100%">standards</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2014</style></year><pub-dates><date><style  face="normal" font="default" size="100%">10/2014</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">http://timreview.ca/article/837</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">4</style></volume><pages><style face="normal" font="default" size="100%">33-39</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Critical infrastructure such as power generation and distribution systems, telecommunications networks, pipelines and pipeline control networks, transportation control networks, financial networks, and government information and communications technology (ICT) have increasingly become the target of cyber-attacks. The impact and cost of these threats, as well as regulatory pressure to mitigate them, have created an impetus to secure these critical infrastructures. Managers have many controls and models at their disposal to help them secure infrastructure technology, including cybersecurity capability maturity models to enable measurement and communication of cybersecurity readiness to top management teams, regulators, and customers, thereby facilitating regulatory compliance, corporate responsibility, and improved brand quality. However, information and awareness is lacking about which models are most appropriate for a given situation and how they should be deployed.

This article examines relevant cybersecurity capability maturity models to identify the standards and controls available to providers of critical infrastructure in an effort to improve their level of security preparedness. These capability models are described and categorized by their relevance to different infrastructure domains, and then recommendations are provided on employing capability maturity models to measure and communicate readiness. This article will be relevant to regulators, critical infrastructure providers, and researchers. </style></abstract><issue><style face="normal" font="default" size="100%">10</style></issue><custom1><style face="normal" font="default" size="100%">Carleton University
Walter Miron is a Director of Technology Strategy at TELUS Communications, where he is responsible for the evolution of their packet and optical networks. He has over 20 years of experience in enterprise and service provider networking conducting technology selection and service development projects. Walter is a member of the research program committee of the SAVI project, the Heavy Reading Global Ethernet Executive Council, and the ATOPs SDN/nFV Working Group. He is also Chair of the Venus Cybersecurity Corporation and a board member of the Centre of Excellence for Next Generation Networking (CENGN) in Ottawa, Canada. Walter is currently a graduate student in the Technology Innovation Management (TIM) program at Carleton University in Ottawa, Canada. </style></custom1><custom2><style face="normal" font="default" size="100%">Carleton University
Kevin Muita is a graduate student in the Technology Innovation Management program at Carleton University in Ottawa, Canada. He has a Bachelor's degree in Technology from Africa Nazarene University in Nairobi, Kenya. He has co-founded two technology startups: a network consultancy company and a systems installation and maintenance company. He has experience in logistics and supply chain management, having managed a Coca-Cola distribution network in Kenya, overseeing a successful 300% increase in sales volume, operations, and service delivery.</style></custom2></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Philip O’Neill</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Protecting Critical Infrastructure by Identifying Pathways of Exposure to Risk</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">critical infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">directed graph</style></keyword><keyword><style  face="normal" font="default" size="100%">modelling</style></keyword><keyword><style  face="normal" font="default" size="100%">path analysis</style></keyword><keyword><style  face="normal" font="default" size="100%">risk analysis</style></keyword><keyword><style  face="normal" font="default" size="100%">simulation</style></keyword><keyword><style  face="normal" font="default" size="100%">strongest-path method</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2013</style></year><pub-dates><date><style  face="normal" font="default" size="100%">08/2013</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">http://timreview.ca/article/714</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">3</style></volume><pages><style face="normal" font="default" size="100%">34-40</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Increasingly, our critical infrastructure is managed and controlled by computers and the information networks that connect them. Cyber-terrorists and other malicious actors understand the economic and social impact that a successful attack on these systems could have. While it is imperative that we defend against such attacks, it is equally imperative that we realize how best to react to them. This article presents the strongest-path method of analyzing all potential pathways of exposure to risk – no matter how indirect or circuitous they may be – in a network model of infrastructure and operations. The method makes direct use of expert knowledge about entities and dependency relationships without the need for any simulation or any other models. By using path analysis in a directed graph model of critical infrastructure, planners can model and assess the effects of a potential attack and develop resilient responses. </style></abstract><issue><style face="normal" font="default" size="100%">8</style></issue><custom1><style face="normal" font="default" size="100%">Deep Logic Solutions
Philip O'Neill is Chief Scientist at Deep Logic Solutions Inc. He holds a PhD in Combinatorics and Optimization from the University of Waterloo, Canada. He is a specialist in operational research and risk analysis, and has additional expertise in mathematical modelling, quantitative analysis, algorithms, and decision support. His career has included 17 years of practice in the Operational Research Division of the Department of National Defence (DND); he has served as chairman of the NATO Panel 7 Specialist Team on the Evaluation of Readiness and Sustainment Policy; and he was chosen by the DND to model dependency relationships among infrastructures in Canada as part of risk analysis for the millennium turnover. Since 2001, he has designed and managed the software development of RiskOutLook, an analytical tool for risk analysis that identifies and quantifies risks that result from dependency relationships. </style></custom1></record></records></xml>