2021-09-09-世界经济论坛-油气供应链安全性分析白皮书_26页_2mb
报告摘要
Summary of "Advancing Supply Chain Security in Oil and Gas: An Industry Analysis"
Core Content
This white paper focuses on the increasing cybersecurity risks in the oil and gas industry due to hyperconnectivity and the complex, integrated nature of modern supply chains. It emphasizes the need for a holistic, risk-informed approach to managing third-party cybersecurity risks, which has become essential for maintaining the integrity, availability, and safety of critical operations. The report outlines a comprehensive framework for third-party risk management, incorporating guiding principles, phases of risk governance, and practical implementation guidelines.
Main Points
-
Cybersecurity Risks in the Oil and Gas Industry: The industry's digital transformation and integration have expanded the attack surface, making third-party systems a potential vector for cyber threats. Examples include the Colonial Pipeline ransomware attack and the Kaseya breach, which demonstrate the cascading impact of supply-chain cyber incidents.
-
Need for a Harmonized Approach: Traditional methods of managing third-party risk are inefficient, leading to redundancy, inconsistency, and blind spots. A unified approach is necessary to ensure consistent cybersecurity standards and effective risk mitigation across the supply chain.
-
Holistic Framework for Third-Party Risk Management: The report proposes a five-phase model for managing third-party risks:
- Planning: Selecting third parties based on internal needs and service nature.
- Assessment and Evaluation: Using a common set of cybersecurity requirements to assess and evaluate third-party environments.
- Contract and Commissioning: Establishing contractual terms and conditions aligned with risk profiles.
- Operation and Monitoring: Implementing continuous monitoring and response mechanisms.
- Offloading: Managing the exit strategy and transition of third-party relationships.
-
10 Key Principles for Cybersecurity Baseline: These principles guide the establishment of a common cybersecurity baseline, including governance, access control, secure-by-design systems, and continuous monitoring.
Key Information
Key Benefits of a Holistic Approach
- Cost and Time Efficiencies: Streamlines information gathering and reduces the time and resources needed for due diligence.
- Multidimensional Risk Coverage: Ensures consistent cybersecurity requirements and aligns with industry frameworks and regulations.
- Transparency: Demonstrates commitment to cybersecurity and builds trust across the supply chain.
Implementation Guidelines
The report provides essential guidelines for implementing a cybersecurity baseline across three main phases:
-
Assessment and Evaluation:
- Develop common cybersecurity requirements aligned with industry standards.
- Define the inherent risk rating of third parties based on four criteria:
- Access to critical IT systems
- Access to critical OT systems
- Access to sensitive information
- Dependency on third-party services for critical business processes
- Use a risk-based scoring model to classify third parties as critical, high, moderate, or low.
-
Contract and Commissioning:
- Establish a consistent contractual taxonomy that aligns with cybersecurity needs and risk profiles.
- Use SLAs and KPIs to define expectations and performance metrics.
-
Operation and Monitoring:
- Share best practices and minimum requirements for continuous monitoring.
- Implement shared assessment models to reduce redundancy and increase efficiency.
Case Studies
-
Shell: Integrates third-party risk management across sourcing, assurance, and IT. Uses data analytics and cybersecurity ratings to monitor and assess risks, ensuring alignment with suppliers.
-
Galp Energia: Implements a third-party risk management programme based on NIST Cybersecurity Framework and a risk-based approach. This includes regular awareness sessions and real-time dashboards to track risk levels.
-
Schneider Electric: Establishes a cross-functional cybersecurity programme to classify suppliers into four risk categories and apply tailored security requirements. It uses shared assessments and cybersecurity ratings to streamline due diligence and improve transparency.
Conclusion
The oil and gas industry must adopt a risk-informed, holistic approach to third-party cybersecurity risk management to ensure long-term resilience and sustainability. This report serves as a blueprint for organizations to align their practices with industry standards and foster collaboration and shared responsibility across the supply chain. It also provides a model for other industries to follow in enhancing their own supply chain security strategies.
Appendices and Contributors
- Appendix A: Provides a third-party risk assessment cheat sheet.
- Appendix B: Offers a taxonomy for categorizing third-party risk levels.
- Contributors: Includes experts from Saudi Aramco, Schneider Electric, PwC, and the Cyber Resilience in Oil and Gas community.
- Acknowledgements: Recognizes the contributions of the multistakeholder community and the World Economic Forum.
- Endnotes: References supporting data and examples, including the Colonial Pipeline and Kaseya incidents.
Final Note
Collaboration and shared understanding are essential for improving cybersecurity resilience in the oil and gas industry. This report aims to trigger discussions and actions to build a more secure and resilient technological ecosystem.
试读结束,高清完整版pdf/doc/ppt,请点下载