FSB全球金融稳定委员会-Effective-Practices-for-Cyber-Incident-Response-and-Recovery_-Consultative-document_22页_1mb
报告摘要
Summary of Effective Practices for Cyber Incident Response and Recovery Consultative Document
Core Content
The Financial Stability Board (FSB) has issued a consultative document outlining effective practices for cyber incident response and recovery (CIRR) in the financial sector. The document serves as a toolkit to help financial institutions and authorities enhance their preparedness, response, and recovery capabilities to mitigate financial stability risks. It is not a binding standard but rather a set of flexible practices that can be adapted based on organizational needs and the evolving cyber threat landscape.
Main Objectives
- To enhance the cyber resilience of financial institutions.
- To ensure efficient and effective response and recovery from cyber incidents.
- To promote interconnectedness and coordination between institutions, third-party providers, and regulatory authorities.
- To support information sharing and cross-border collaboration.
Key Components and Practices
The toolkit is structured around seven components and includes 46 effective practices, tailored to the organization's size, regulatory environment, and the nature of the cyber incident.
1. Governance
- Organisation-wide governance framework aligns CIRR with the overall risk management strategy.
- Board and senior management are responsible for oversight and implementation of CIRR activities.
- Defined roles and responsibilities for CIRR, including the Incident Owner, Media Spokesperson, and Scribe/Independent Observers.
- Executive sponsorship is crucial for promoting awareness and accountability.
- Culture of reporting and learning from mistakes is encouraged through training and leadership.
- Funding is allocated based on risk and potential financial stability implications.
- Human resources are managed through training, job rotations, and knowledge sharing between organizations.
- Metrics are used to assess the impact of cyber incidents and the performance of CIRR activities.
2. Preparation
- Policies are developed to guide CIRR activities and ensure compliance with regulatory and legal requirements.
- Plans and playbooks are created for different CIRR scenarios and are regularly updated.
- Communication strategies are established to inform internal and external stakeholders during an incident.
- Scenario planning and stress testing are used to simulate high-impact, low-probability cyber events.
- Security Operations Centre (SOC) is maintained to detect, investigate, and respond to cyber incidents.
- Disaster recovery sites are used to replicate critical systems and data, ensuring business continuity.
- Forensic capabilities are developed to preserve evidence and analyze control failures.
- Technology solutions and vendors are implemented to support policies, with diversification to avoid over-dependency.
- Supply chain management includes risk assessments and contractual SLAs with third-party providers.
3. Analysis
- Cyber incident taxonomy is used to classify incidents based on type, threat actors, delivery channels, and impact.
- Severity assessment frameworks are employed to determine the urgency of response.
- System and transaction logs are collected and analyzed to understand the incident and its root causes.
- Inputs for analysis include threat intelligence, log data, and stakeholder feedback.
4. Mitigation
- Mitigation efforts focus on reducing impact on business and system security.
- Additional considerations include maintaining customer trust, ensuring legal compliance, and preventing reputational damage.
- Tools for data breaches, data integrity loss, and ransomware events include automated response systems, encryption, and backup solutions.
- Integration with third-party providers is supported through shared incident response protocols and SLAs.
- Additional tools could include real-time monitoring systems and threat intelligence platforms.
- Overlap between mitigation and restoration may occur in cases where the same tools or procedures are used for both phases.
5. Restoration
- Tools and processes for restoration include backup systems, failover mechanisms, and recovery protocols.
- Prioritization of restoration is guided by predefined plans, metrics, and business recovery objectives.
- Minimizing undesirable outcomes during restoration involves careful data validation and controlled system reactivation.
6. Improvement
- Exercises and drills are considered effective if they simulate real-world scenarios and test response capabilities.
- Cross-sectoral and cross-border exercises are hindered by legal, jurisdictional, and operational differences.
- Technological aids such as simulation tools, AI-driven analytics, and automated response systems are considered most useful for improving CIRR.
7. Coordination and Communication
- Coordination activities are distinct from general communication and involve structured collaboration between internal and external stakeholders.
- Alternative communication channels are prepared in case traditional methods are unavailable.
- Additional information to be shared with authorities includes technical details, incident timelines, and potential sector-wide implications.
Key Information
- The FSB aims to coordinate global efforts to enhance financial sector cyber resilience.
- The toolkit is developed based on survey responses, existing standards, and case studies.
- The document invites public consultation to gather feedback on the effectiveness of the practices and to suggest improvements.
- Responses should be submitted to CIRR@fsb.org by Monday, 20 July 2020.
- The toolkit is not a prescriptive standard but a set of options to be adapted by each organization.
- Cyber resilience is critical for maintaining financial stability, especially in the context of interconnected systems and third-party dependencies.
Conclusion
This consultative document emphasizes the importance of structured governance, preparation, analysis, mitigation, restoration, improvement, and coordination in managing cyber incidents. It highlights the need for collaboration between public and private sectors, flexible and adaptive practices, and continuous improvement through exercises and learning from past incidents. The FSB encourages feedback to refine and enhance the toolkit for broader application across the financial ecosystem.
试读结束,高清完整版pdf/doc/ppt,请点下载