国际清算银行-北极星项目:CBDC系统的安全和弹性框架(英)-2023.7-68页_3mb
报告摘要
Summary of Project Polaris: Security and Resilience Framework for CBDC Systems
Introduction
Project Polaris by BIS Cyber Resilience Coordination Centre provides a framework for securing Central Bank Digital Currency (CBDC) systems. CBDCs are critical infrastructure, vulnerable to cyber threats such as attacks from nation-states, organized crime, and advanced persistent threats (APTs). The framework emphasizes a risk-based approach, leveraging modern technologies and end-to-end ecosystem collaboration to manage complexity and mitigate risks.
Framework Overview
The framework adopts a seven-step iterative process based on NIST's Cybersecurity Framework, adapted for CBDCs:
- Prepare: Establish management commitment, governance, and capabilities for security and resilience.
- Identify: Assess information assets, external dependencies, and define security requirements.
- Protect: Implement technical and non-technical controls to safeguard systems, including network segmentation and application security.
- Detect: Deploy monitoring tools and technologies to identify threats in real-time.
- Respond: Respond to incidents with dedicated teams, ensuring rapid containment and recovery.
- Recover: Restore services and system integrity based on predefined objectives.
- Adapt: Continuously improve through incident learning and technology updates.
Key themes include baseline controls, IT modernization (e.g., DevSecOps, zero-trust security), DLT-specific considerations, and CBDC-focused enhancements.
Threat Landscape
CBDC systems face a diverse threat landscape, including:
- Threat actors: Nation-states, organized crime, hacktivists, insiders, lone hackers, and natural disasters.
- Threat events: DDoS attacks, malware, cryptographic key compromises, and exploits of new technologies like DLT or smart contracts.
- Risks: Confidentiality breaches, integrity failures, availability issues, reputational damage, and financial losses.
Application and Roles
- Roles and Responsibilities: Central banks lead strategy and oversight, with involvement from financial institutions, technology providers, and end users. Clear accountability includes security teams, program managers, and ecosystem participants.
- Path to Readiness: Implement control objectives using models like Capability Maturity Model Integration (CMMI). Develop plans, execute with stakeholders, and iterate based on risk tolerance and incident learnings.
Conclusion
The framework supports central banks in navigating CBDC risks through a collaborative, iterative approach. It must evolve with emerging threats and technologies to ensure robust security and resilience, requiring public-private partnerships and continuous improvement.
试读结束,高清完整版pdf/doc/ppt,请点下载