The Need for Systems Thinking
Loopy Diagram

The Need for Systems Thinking

With complex systems, behavior is not determined by cause-effect exclusively. That is, not everything is chains of events with a root cause. Rather, a system's behavior emerges from the structure of feedback loops associated with the system, something understood by the use of systems thinking. The graphic with this article shows a simple structure of feedback loops.

Systems thinking is an approach (a philosophy?) that sees the world and its systems in terms of wholes and relationships, rather than breaking it down, or decomposing it, into parts. It considers how the pieces interact to create the whole. For a system, it requires understanding relationships with the larger world - the environment, humans, other systems.

Security can not be completely analyzed in threat based or threat informed ways, as commonly practiced. Nor can it be completely analyzed via vulnerability assessments. These are approaches rooted in cause->effect chains, more precisely a threat A exploits a vulnerability B to create an effect C, that is, A->B->C.

What is needed to think in terms of feedback loops that extent beyond a system's boundary. Doing so sees the system completely, or at least more completely. For example, Peter Lewycky in 1987 described that explaining safety accidents/incidents can be done in terms of constraints, conditions, and mechanisms. Mechanisms are the chain of events, but to understand them and best prevent incidents in the future, the need is to understand the conditions or lack of conditions that permitted the chain of events. Finally, one needs to understand the constraints or lack of constraints that permitted the conditions. These conditions and constraints, and their lack, are what go beyond a system's boundary.

William "Dollar" Young and Nancy Leveson wrote about this about 11 years ago in "Systems Thinking for Safety and Security". If we take our feedback loops and turn them a few degrees, we see system behavior of the system with feedback loops that amount to closed loop controls (classic system controls, not NIST SP 800-53 use of that term). When we look at the loops, we can see where we need to add loops to achieve safe and secure behavior, we can see where the loops can go wrong or are susceptible to manipulation by malicious actors.

Systems Thinking is a foundational skill of systems engineering - it needs to be one for systems security engineers and really any security engineer. The community needs to get beyond thinking of risk as a function of threat and vulnerability only - not to mention just get beyond it is all about risk management as the means to achieve security. Need systems thinking to achieve assured function as part of intended behaviors and outcomes.

Unless otherwise stated, all views expressed are mine and don’t necessarily reflect those of my employer or MITRE sponsors.

Mark: Restating the obvious, but there there is a lot of smoke blocking the light out there. Good topic and well worth additional foot stomping. Thanks!

Mark W.

Security is a matter of engineering, not compliance. Co-author NIST SP 800-160 Volume 1.

6 个月

This apparently struck a nerve, or people are bored this weekend. This one is already #10 in impressions for the last year and by the time I finish typing may be #9. Fred Robinson ScD ESEP, Chris Glazner - who knew systems thinking could be so popular.

回复
Pons Mudivai Arun

Curious about systems' interconnectedness, emergence, and impact

6 个月

Well said Mark W.,?Cyber mess can't be solved with the same level of skills that created it (ie, linear mental model like threat A exploits a vulnerability B to create an effect C, that is, A->B->C. ).?what we need is the clear mental model of the current system behavior and what does it take to improve the same to the desired state. In that context, system thinking can illuminate multiple perspectives to make the target system behavior simple and beautiful.

Max Allway

Systems Thinking Trusted Exec/BOD Advisor, Toyota Material Handling - McKinsey - Booz Allen _ MITRE Alum

6 个月

Mark, thanks for continuing to press the systems thinking approach. Unfortunately it seems to be a difficult approach for many people!??

Shaharyar Khan

AIG | Researcher at MIT | Cybersecurity | Nuclear Energy

6 个月

Love this!

要查看或添加评论,请登录

Mark W.的更多文章

  • RIF Incoming

    RIF Incoming

    My company is preparing for its first broad Reduction in Force (RIF) in a generation - though there have been targeted…

    5 条评论
  • The New Triad?

    The New Triad?

    Unless otherwise stated, all views expressed are mine and don’t necessarily reflect those of my employer or MITRE…

    3 条评论
  • Confusion: Social Security

    Confusion: Social Security

    Last time I did an article on confusion around the chaos of financial aspects, with intent in time to get back it with…

    1 条评论
  • Red Tape

    Red Tape

    Reading through Senator Roger Wicker's Restoring Freedom's Forge this week, the quote of Admiral Hyman Rickover at the…

    5 条评论
  • Confusion

    Confusion

    For a second post, and maybe the immediate next few, I thought I would talk to the confusion around income generation…

    2 条评论
  • Ron Ross

    Ron Ross

    With Ron Ross' announced retirement this past week (Post | Ron Ross' Retirement), I thought I'd take some time to talk…

    4 条评论
  • Embracing Opportunity for Change

    Embracing Opportunity for Change

    My current company allows easy transitions to part time - and I've just ended the second week of it. I do see this as a…

    5 条评论
  • Evidence-Based Assurance

    Evidence-Based Assurance

    Some readers may have heard Michael McEvilley and/or I speak to evidence-based assurance. I forget when we even started…

    1 条评论
  • Visiting McNamara's Fallacy and Folly

    Visiting McNamara's Fallacy and Folly

    Talking about a pivot - I was about one thing on data/evidence fallacies with things security/resilience, and in…

    2 条评论
  • "Security" or Pseudo-Science

    "Security" or Pseudo-Science

    David Slater is a great follow. Safety and Security are closer related than most realize - much of what Michael…

    8 条评论

社区洞察

其他会员也浏览了