DOE OSTI2023
High-reliability systems are characterized by catastrophic implications in the event of failure. These implications can include substantive damage to the environment, social order, and loss of life. Examples of high-reliability systems include nuclear submarines, nuclear reactors, the electric grid, and nuclear weapons. Due to the catastrophic implications of failure, there are heightened awareness and control mechanisms surrounding related data and information. However, defining the difference between data and information is often ambiguous across scholarly disciplines and in United States policy and legislation. For high-reliability systems, the implications of ambiguity between data and information may affect the security of United States interests and even cost lives. For security, data are raw facts or figures without context, while information is the compilation or articulation of data that forms context. Security depends on clarity in the differences between data and information and how to control them. Control is necessary to ensure that data and information are not unintentionally released to foreign governments, the public, or those without need-to-know. A primary concern in the practice of security is the control of data to avoid the unintended conversion to information. Intra-institutionally, this control is highly complex given the amalgam of legacy data systems and the numerous and constantly evolving nature of modern data systems that were not necessarily designed to be integrated. The complexity of this concern is augmented when institutions are part of interinstitutional collaborations or networks of public-private partnerships that share data and information. Additionally, institutions that share data as a function of policy and legislative action— particularly formally integrated data and information system infrastructures—may be at higher security risk. This paper will present an intra-institutional paradigm that utilizes and integrates concepts from numerous disciplines to frame a critical and underspecified practical issue in security—controlling for the unintended conversion of data to information.
45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗