FSB全球金融稳定委员会-Effective-Practices-for-Cyber-Incident-Response-and-Recovery_-overview-of-public-consultation_3页_152kb
报告摘要
Cyber Incident Response and Recovery Summary
Overview
On 20 April 2020, the Financial Stability Board (FSB) published a consultative document titled Effective Practices for Cyber Incident Response and Recovery (CIRR), proposing a toolkit to assist organisations in managing cyber incidents. This toolkit builds upon the FSB Cyber Lexicon, developed in 2018 to enhance communication and support cyber resilience efforts across the financial sector. The FSB received 58 responses from various stakeholders, including banks, insurers, industry associations, and public authorities, and held four virtual outreach meetings with over 300 private sector participants to gather feedback. The final version of the toolkit incorporates these insights to better address the evolving challenges in cyber incident response and recovery.
Core Content and Main Issues
The summary highlights the following main issues raised during the public consultation:
-
Lessons from the COVID-19 pandemic: Many respondents noted that the shift to remote work introduced new challenges in cyber incident coordination and response. Activities such as documenting digital evidence and conducting forensic analysis became more difficult. Additionally, phishing tactics evolved to exploit the situation. These insights were integrated into the final toolkit by advising organisations to incorporate such lessons into their scenario analysis, plans, and overall cyber resilience strategies.
-
Toolkit as a reference guide: Despite the consultative document stating that the toolkit is not a standard or regulation, some respondents misunderstood its purpose. The final toolkit includes an introduction clarifying its role as a resource and reference guide for SSBs and authorities.
-
Proportionality and flexibility: Respondents emphasized the need for the toolkit to be adaptable to the size, complexity, and maturity levels of different organisations. The final toolkit reflects this by offering a range of effective practices that organisations can choose based on their specific needs and risks to the financial ecosystem.
-
Cyber Lexicon and coordination: Some respondents suggested updating the FSB Cyber Lexicon to improve clarity and encourage harmonized practices. They also highlighted the need for enhanced coordination among authorities in reporting cyber incidents. The FSB plans to consider these suggestions as part of its future work programme.
-
Clarification of benefits for authorities: Respondents sought to understand how authorities could use the toolkit. The final version clarifies that it aims to support SSBs and authorities in developing guidance on cybersecurity practices.
CIRR Components and Feedback
The FSB's CIRR toolkit consists of seven components, focusing on the Respond and Recover functions. These components assume that incidents have already been identified and not prevented. While most respondents' cybersecurity frameworks included these components, some suggested the inclusion of additional elements such as "Identification" and "Prevention". These were not incorporated into the final toolkit.
Some respondents felt that the components were not well sequenced or that the tools were too broad. For example, "Preparation" was rebranded to "Planning and preparation" to better reflect its purpose of being in place before an incident occurs. Similarly, "Restoration" was renamed to "Restoration and recovery" to include data recovery as a key aspect.
Enhancements to the Toolkit
The final toolkit includes the following enhancements:
-
Substantive modifications: Out of the 46 tools in the consultative document, 37 were modified to include additional examples and clarify their objectives. The remaining 9 tools remained largely unchanged.
-
Three new tools added: As a result of the consultation, three new tools were introduced, increasing the total number of tools to 49.
-
Governance component improvements: The most significant feedback was related to the Governance component. Tool 2, which outlined the board's roles and responsibilities, was criticized for being too prescriptive and assigning operational tasks to the board. The final toolkit clarifies the distinction between the board's and senior management's roles.
-
Role flexibility: Tool 3, which defined roles such as incident owner, scribe, and media spokesperson, was revised to remove prescriptive role assignments. Instead, it now provides tools that organisations can adopt based on their size, complexity, and risk profile.
Conclusion
The FSB's final toolkit for cyber incident response and recovery reflects the feedback received from stakeholders, particularly in light of the challenges posed by the COVID-19 pandemic. It emphasizes flexibility, proportionality, and the importance of incorporating lessons from real-world experiences. The toolkit serves as a guide for organisations to enhance their cyber resilience and support authorities in developing consistent cybersecurity practices.
试读结束,高清完整版pdf/doc/ppt,请点下载