【IMF】中央银行数字货币生态系统的网络弹性-2024_54页_1mb
报告摘要
Summary of Cyber Resilience of the Central Bank Digital Currency Ecosystem
Core Content
This Fintech Note from the International Monetary Fund (IMF) examines the cyber resilience of the Central Bank Digital Currency (CBDC) ecosystem. It outlines the key cyber risks associated with CBDCs and discusses the design and implementation considerations necessary to build a secure and resilient system.
Main Points
Overview of CBDC and Cyber Risk
- Over 100 central banks globally are exploring CBDCs to modernize payment systems.
- CBDCs are exposed to both digital and payment system risks.
- Cyber risk is a subset of operational risk and can be a source or consequence of failure in processes, people, or technology.
- Cyber risk is unique due to its evolving nature, the use of advanced technologies, and the human element in attacks.
Cyber Risk Perimeter
- The CBDC ecosystem has three key elements of cyber risk:
- Currency Lifecycle: From creation to destruction.
- Transactions and Value Transfer: Between individuals and merchants.
- Sensitive Information: Collected from users, merchants, and transactions, which needs protection in transit and at rest.
Cyber Threats and Attack Vectors
- Cyber threats include:
- Denial of Service (DoS/DDoS): Overwhelming network bandwidth.
- System intrusion and data infiltration: Unauthorized access to data and systems.
- Malware, ransomware, and wiperware: Disrupting operations and encrypting data.
- Phishing and social engineering: Exploiting human behavior.
- Third-party and supply chain attacks: Targeting less secure systems.
- Cryptographic key compromise: Leading to fraud and data breaches.
- Threat actors range from nation-states to organized crime, insiders, and hacktivists, each with distinct motivations and resources.
Cyber Risk Implications
- Cyberattacks can cause service outages, data breaches, fraud, and loss of user confidence.
- The impact of cyber incidents can range from millions to billions of USD, depending on the scenario.
- Cyber risks in an interconnected environment can spread rapidly, creating cascading effects across the ecosystem.
Design Options and Cybersecurity Implications
The note explores five key design options for CBDCs and their cybersecurity implications:
-
Distribution Model
- Influences how CBDCs are issued and managed.
- Impacts the resilience of the system and the security of the infrastructure.
-
Token or Account-Based Design
- Token-based systems may offer greater scalability and privacy.
- Account-based systems provide traceability and regulatory compliance.
- Each has different security trade-offs.
-
Ledger Design
- Centralized vs. distributed ledger technology (DLT) approaches.
- DLT offers transparency and decentralization but may introduce complexity and security challenges.
-
Offline Functionality
- Ensures continuity of service during network disruptions.
- Reduces the attack surface but requires secure offline storage and processing.
-
Use of Third Parties for Critical Services
- Third-party involvement can increase complexity and interdependencies.
- Requires strict oversight, contractual safeguards, and risk management.
Foundational Requirements and Good Practices
High-Level Principles for Cybersecurity
- Confidentiality, Integrity, and Availability (CIA Triad) are the core principles.
- Zero-Trust Principle is emphasized: never trust, always verify.
Foundational Requirements
- Secure infrastructure and robust communication networks.
- Digital literacy and cyber risk awareness among users.
- Technological maturity of financial institutions.
- Collaboration among stakeholders.
- Stable geopolitical environment.
Good Practices
- Cyber Incident Response Plan: Predefined procedures to mitigate consequences.
- Multi-Factor Authentication (MFA): Enhances user authentication.
- Defense-in-Depth Strategy: Combines people, processes, and technology to protect against threats.
- Regular Patch Management: Ensures systems are up-to-date and secure.
- Penetration Testing: Identifies vulnerabilities and strengthens defenses.
Cyber Resilience and Project Management
- Cyber resilience must be integrated into the CBDC project lifecycle.
- Emphasizes risk mapping, security by design, and continuous monitoring.
Conclusion and Recommendations
- A retail CBDC ecosystem is more complex and interconnected than a wholesale one.
- Cyber resilience is crucial for maintaining trust and ensuring the smooth operation of the CBDC system.
- Early consideration of security and resilience is essential in the design phase.
- Lessons from existing cybersecurity frameworks and CBDC experiments can inform the development of security guidance.
Key Takeaways
- CBDCs are high-value targets for cyber threats, including nation-states and cybercriminals.
- Cyber risk is not only a technical challenge but also a people and process issue.
- AI and other emerging technologies can both enhance and threaten cybersecurity.
- Resilience and security must be built into the architecture and design of the CBDC system from the outset.
- Collaboration, training, and continuous improvement are essential for a secure CBDC ecosystem.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载