Enhancing Resilience through Cyber Incident Data Sharing and Analysis
ثبت نشده
چکیده
This document outlines the benefits of a trusted cyber incident data repository that enterprise risk owners and insurers could use to anonymously share sensitive cyber incident data and is the first in a series of white papers. This paper outlines the potential benefits of a trusted cyber incident data repository that enterprise risk owners and insurers could use to anonymously share, store, aggregate, and analyze sensitive cyber incident data. Optimally, such a repository could enable a novel information sharing capability among the Federal government, enterprise risk owners, and insurers that increases shared awareness about current and historical cyber risk conditions and helps identify longer-term cyber risk trends. This information sharing approach could help not only enhance existing cyber risk mitigation strategies but also improve and expand upon existing cybersecurity insurance offerings. Rooted in rich repository data, new analytics products could help inform more effective private and public sector investment in these complementary cyber risk management categories. Specifically, such products could help promote greater understanding about the financial and operational impacts of cyber events, the effectiveness of existing cyber risk controls in addressing them, and the new kinds of products and services that cybersecurity solutions providers should develop to meet the evolving risk mitigation needs of their customers. These developments, in turn, could help drive the critical infrastructure protection and national resilience goals outlined in White House Executive Orders 13636 and 13691 and advance the risk-based approach of the National Institute of Standards and Technology's (NIST) Cybersecurity Framework. To develop the repository concept more fully – and to assess the challenges and opportunities that the concept entails – the Department of Homeland Security's (DHS) National Protection and Programs Directorate (NPPD) established the Cyber Incident Data and Analysis Working Group (CIDAWG) under Critical infrastructure Partnership Advisory Council (CIPAC) auspices. The CIDAWG aims to generate key findings and conclusions about the following issues: (1) the value proposition of a repository; (2) the type and scope of non-personally identifiable cyber incident data that should be shared into a repository; (3) how repository participation should be incentivized; and (4) how a repository should be structured. The CIDAWG is comprised of cyber risk mitigation experts (chief information security officers (CISOs), cybersecurity solutions providers, and other cybersecurity professionals), cyber risk transfer experts (insurers), and other cybersecurity subject matter experts from the academic and scientific communities. During the first stage of their work, the CIDAWG participants agreed that …
منابع مشابه
A Public-Private-Partnership Model for Na- tional Cyber Situational Awareness
The information age has led to the merger of various infrastructures, from both business and governmental sectors and their functions, such as information technology, communication and transport systems, banking and finance, energy supply and process control systems. The protection of these systems is essential to resilience and reliability of critical infrastructures and their key resources, c...
متن کاملAn Evolution Roadmap for Community Cyber Security Information Sharing Maturity Model
Cyber security has become one of the most important challenges, which is especially true for communities. A community generally consists of all of the entities within a geographical region, including both public and private infrastructures. Cyber attacks and other cyber threats can result in disruption and destruction of critical services and cause potentially devastating impacts in a community...
متن کاملAn Overview of Pilot Projects in Support of Critical Infrastructure Resilience
This paper describes two pilot projects undertaken in the Province of British Columbia (BC) by the Defence Research and Development Canada Centre for Security Science (DRDC CSS) in partnership with Emergency Management British Columbia (EMBC) and local communities. The pilot projects occurred between May 2012 and September 2013 with three communities of population ranging from 5000 to 90,000. V...
متن کاملA problem shared is a problem halved: A survey on the dimensions of collective cyber defense through security information sharing
The Internet threat landscape is fundamentally changing. A major shift away from hobby hacking toward well-organized cyber crime can be observed.These attacks are typically carried out for commercial reasons in a sophisticated and targeted manner, and specifically in a way to circumvent common security measures. Additionally, networks have grown to a scale and complexity, and have reached a deg...
متن کاملIs Cyber Resilience in Medical Practice Security Achievable?
Australia is moving to a national e-health system with a high level of interconnectedness. The scenario for recovery of such a system, particularly once it is heavily relied upon, may be complex. Primary care medical practices are a fundamental part of the new e-health environment yet function as separate business entities within Australia’s healthcare system. Individually this means that recov...
متن کامل