2021-09-01-哈佛大学-综合努力_重新思考关键基础设施的网络安全(英)_9页_159kb
报告摘要
The paper "Integration of Effort: Rethinking Cybersecurity for Critical Infrastructure" examines the challenges of securing critical infrastructure against cyber threats. It argues that the current policy framework is flawed due to its reliance on improvised measures and provides four key recommendations for change.
Executive Summary: Critical infrastructure, defined as systems vital to society, faces cyber threats from private owners and sophisticated actors. Government engagement must be more effective through tailored partnerships with industry, as existing voluntary collaborations, regulations, and direct aids have uneven success.
Background: Critical infrastructure sectors in the U.S. face vulnerabilities from digitalization and interconnectivity. Ownership by private firms means the government must intervene, but current strategies like information-sharing centers (ISACs) and regulations are insufficient because they lack standardization and real-world applicability.
Analysis: The policy framework is inadequate for several reasons: information-sharing is inconsistent, regulatory mandates do not adapt to dynamic threats and may hinder investment, and direct government aid favors large firms over smaller ones due to ad hoc approaches.
Recommendations: Four elements are proposed to enhance cybersecurity: tailor policies to each sector's unique dynamics, focus on systemically important firms and functions, establish a joint war room for collaboration, and provide targeted assistance to smaller operators. This involves sector-specific reviews, full industry partnership, and avoiding top-down regulation, aiming for true integration.
Private sector involvement and adaptive mechanisms are crucial for long-term success.
试读结束,高清完整版pdf/doc/ppt,请点下载