2018年-FSB全球金融稳定委员会_Cyber_Lexicon_19页_493kb
报告摘要
Cyber Lexicon Summary
Introduction
The Cyber Lexicon is a document published by the Financial Stability Board (FSB) on 12 November 2018. It aims to provide a common understanding of cyber security and cyber resilience terminology across the financial sector and with other industry sectors. The lexicon was developed in response to the growing threat of cyber incidents, such as the 2016 Bangladesh Bank attack, the 2017 WannaCry ransomware attack, and the Equifax data breach. These incidents highlighted the need for a unified framework to enhance the sector's ability to mitigate and respond to cyber risks.
The FSB was asked by the G20 to conduct a stocktake of existing regulations and supervisory practices on cyber security in the financial sector, which led to the development of this lexicon. It is intended to support the work of the FSB, standard-setting bodies (SSBs), authorities, and private sector participants in addressing cyber risks, but it is not a legal document and should not be used for legal interpretation.
Core Objectives
The main objectives of the Cyber Lexicon are:
- To promote a common understanding of cyber security and cyber resilience terminology across the financial sector.
- To support assessing and monitoring financial stability risks associated with cyber incidents.
- To facilitate information sharing between public and private entities.
- To assist in the development of guidance and effective practices by the FSB and SSBs.
The lexicon is not mandatory and serves as a helpful tool for collaboration and communication.
Development Process
The FSB developed the lexicon through a collaborative and consultative process:
- A working group of experts, chaired by the U.S. Federal Reserve Board, was formed.
- Members were selected based on their expertise in cyber security and cyber resilience regulation and supervision.
- The working group included representatives from all major SSBs: BCBS, CPMI, IAIS, and IOSCO.
- The lexicon was developed with input from external organizations such as ISO, ISACA, the SANS Institute, and NIST.
- A public consultation was conducted, and the final version reflects the comments received during this process.
- A companion report summarises public feedback and explains how it was resolved.
Selection of Terms
The terms included in the lexicon were selected based on the following criteria:
- Relevance to the financial sector: The lexicon focuses on terms that are essential for understanding and managing cyber risks within the financial sector.
- Scope limitation: It is not intended to be a comprehensive list of all cyber-related terms, but rather a core set of definitions relevant to the FSB’s objectives.
- Exclusion of technical terms: Technical ICT terms are generally excluded unless they are deemed essential for the lexicon’s purpose.
- Exclusion of general business terms: Terms like Risk, Risk Assessment, and Business Continuity Plan are excluded as they are not unique to cyber security or cyber resilience.
Criteria for Developing Definitions
The working group followed these key criteria when developing definitions:
- Reliance on existing sources: Definitions were drawn from established standards and frameworks such as NIST, ISO, and ISACA.
- Comprehensiveness: Each definition was crafted to include all key elements necessary to understand the term in the context of cyber security and cyber resilience.
- Plain language: Definitions were written in clear, concise language to ensure accessibility and avoid unnecessary technical jargon.
- Context-specific relevance: Where terms may have broader meanings, the lexicon provides context-specific definitions relevant to cyber security and cyber resilience.
Key Terms and Definitions
| Term | Definition |
|---|---|
| Access Control | Ensuring access to assets is authorised and restricted based on business and security requirements. |
| Accountability | Ensuring the actions of an entity can be uniquely traced back to that entity. |
| Advanced Persistent Threat (APT) | A sophisticated threat actor that persists over time, adapts to defenses, and is determined to achieve its objectives. |
| Asset | Anything of tangible or intangible value that requires protection, including people, information, infrastructure, and reputation. |
| Authenticity | The property that ensures an entity is what it claims to be. |
| Availability | The property of being accessible and usable by an authorised entity on demand. |
| Campaign | A coordinated set of adversarial activities targeting one or more specific entities over a period of time. |
| Compromise | A violation of the security of an information system. |
| Confidentiality | The property that ensures information is not disclosed to unauthorised individuals or systems. |
| Course of Action (CoA) | Actions taken to prevent or respond to a cyber incident, including both technical and non-technical measures. |
| Cyber | Relating to, within, or through the interconnected information infrastructure. |
| Cyber Incident | A cyber event that jeopardises cyber security or violates security policies. |
| Cyber Resilience | The ability of an organisation to continue its mission despite cyber threats and to recover quickly from incidents. |
| Cyber Risk | The combination of the probability of a cyber incident and its potential impact. |
| Cyber Security | The protection of information and information systems through the cyber medium, including properties like confidentiality, integrity, and availability. |
| Cyber Threat | A circumstance that has the potential to exploit vulnerabilities and adversely affect cyber security. |
| Data Breach | A security compromise leading to the unlawful or accidental destruction, loss, alteration, or disclosure of data. |
| Defence-in-Depth | A security strategy that integrates people, processes, and technology to create multiple layers of protection. |
| Denial of Service (DoS) | Prevention of authorised access to information or systems, or the disruption of their operations. |
| Distributed Denial of Service (DDoS) | A DoS attack carried out using multiple sources simultaneously. |
| Exploit | A method to breach the security of an information system through a vulnerability. |
| Identity and Access Management (IAM) | The process of identifying and managing user access to information systems. |
| Incident Response Team (IRT) | A team responsible for managing cyber incidents throughout their lifecycle. |
| Indicators of Compromise (IoCs) | Signs that a cyber incident may have occurred or is occurring. |
| Information Sharing | The exchange of data, information, or knowledge to manage risks or respond to events. |
| Information System | A set of components, including applications, services, and operating environments, that handle information. |
| Integrity | The property of accuracy and completeness of information. |
| Malware | Software designed with malicious intent that can cause harm to entities or their systems. |
| Multi-Factor Authentication | Verification of a user's identity using two or more factors (knowledge, possession, biometric). |
| Non-repudiation | The ability to prove the occurrence of an event and its origin. |
| Patch Management | The systematic process of identifying, deploying, and verifying software updates. |
| Penetration Testing | A method to test the security of an information system by simulating threats. |
| Threat Actor | An individual, group, or organisation believed to have malicious intent. |
| Threat Assessment | A formal evaluation of the threat to an organisation and its nature. |
| Threat Intelligence | Aggregated and analysed threat information used to support decision-making. |
| Threat-Led Penetration Testing (TLPT) | A simulation of real-world threats to test an entity’s cyber resilience. |
| Threat Vector | The method or path used by a threat actor to access a target. |
| Traffic Light Protocol (TLP) | A system to define the appropriate audience for information sharing. |
| Verification | The confirmation that specified requirements have been met. |
| Vulnerability | A weakness or flaw in an asset or control that can be exploited by a threat. |
| Vulnerability Assessment | A systematic examination of an information system to identify security deficiencies and evaluate security measures. |
Conclusion
The Cyber Lexicon serves as a common terminology tool to enhance understanding and cooperation across the financial sector in addressing cyber security and cyber resilience. It is designed to support regulatory and supervisory efforts by providing clear, standardised definitions that are relevant to the financial sector, while avoiding overly technical or general terms. The lexicon was developed through collaboration with various stakeholders, including SSBs, industry experts, and international standards bodies, and is based on existing frameworks and standards. It is intended to be a supportive tool, not a binding legal document, and is meant to facilitate cross-border cooperation and effective risk management in the financial sector.
试读结束,高清完整版pdf/doc/ppt,请点下载