世界经济论坛《油气供应链安全性分析白皮书》-26页_2mb
报告摘要
Summary of "Advancing Supply Chain Security in Oil and Gas: An Industry Analysis"
Core Content
This white paper from the World Economic Forum, in collaboration with Saudi Aramco, Schneider Electric, and PwC, outlines a holistic and harmonized approach to managing third-party cyber risks in the oil and gas industry. It emphasizes the need for a unified framework to ensure cybersecurity resilience across the entire supply chain, given the increasing complexity and interconnectivity of modern industrial systems.
The report highlights the growing cyber risks due to the industry's digital transformation and hyperconnectivity, which have expanded the attack surface and introduced new vulnerabilities. It underscores the importance of managing these risks throughout the third-party life cycle, from planning and assessment to operation, monitoring, and offloading.
Main Points
- Cybersecurity Risks: The oil and gas industry is increasingly exposed to cyber risks due to the integration of third-party services, cloud computing, and digital ecosystems. These risks can lead to significant operational disruptions, financial losses, and reputational damage.
- Third-Party Cyber Risks: The expansion of third-party relationships has created new challenges, including inconsistent risk assessment methods, redundant evaluations, and lack of transparency. This leads to inefficiencies and blind spots in cybersecurity management.
- Holistic Risk Management: A unified and streamlined approach to third-party risk management is essential to ensure consistency, accuracy, and efficiency. This includes a common set of requirements, shared assessments, and continuous monitoring.
- Key Benefits: A holistic approach offers cost and time efficiencies, multidimensional risk coverage, and transparency. It enables organizations to reduce operational overhead, align with industry standards, and build trust across the supply chain.
- Guiding Principles: The report outlines 10 key principles for establishing a common cybersecurity baseline, including governance, employee education, access control, secure design, and incident response planning.
Key Implementation Phases
- Planning: Organizations should plan and select third parties based on the nature of the service and internal requirements. This includes identifying the associated risks and engaging with procurement departments early in the process.
- Assessment and Evaluation: This phase involves evaluating the cybersecurity posture of third parties using a standardized set of requirements and assessment methodologies. The goal is to identify residual risks and ensure alignment with industry frameworks.
- Contract and Commissioning: Clear contractual terms and conditions should be established, incorporating cybersecurity requirements, service-level agreements (SLAs), and key performance indicators (KPIs).
- Operation and Monitoring: Continuous monitoring and reassessment of third-party performance and risk profiles are necessary. This includes setting monitoring requirements, timelines, and consequence management protocols.
- Offloading: Organizations must have a strategy for terminating relationships with third parties in a secure and efficient manner, considering reasons such as underperformance or transition to another provider.
Case Studies
Shell
Shell has integrated third-party risk management across sourcing, assurance, and IT. It uses data analytics, security ratings, and a sourcing engine to assess and monitor risks. This approach allows Shell to proactively manage evolving risks and ensure the health and resilience of its business systems.
Galp Energia
Galp Energia has adopted a risk-based third-party risk management program aligned with the NIST Cybersecurity Framework. It uses questionnaires and technical assessments to evaluate suppliers, and provides real-time dashboards and awareness materials to internal stakeholders and suppliers. This has led to improved cybersecurity ratings and supplier cooperation.
Schneider Electric
Schneider Electric has implemented a cross-functional cybersecurity program that classifies suppliers into four categories (critical, high, moderate, low) based on their risk profile. The program includes a set of 39 cybersecurity baseline requirements, which are aligned with the 10 guiding principles. It also promotes shared assessments and continuous monitoring with critical suppliers.
Key Information
- The report bridges information from multiple existing frameworks, including NIST CSF and ISO 27001/2, to provide a practical guide for cybersecurity leaders in the oil and gas sector.
- The implementation of a common baseline is essential to reduce inefficiencies, redundancies, and blind spots in third-party risk management.
- The paper provides actionable guidance, methodologies, and examples to help organizations adopt a more effective and consistent approach to managing cyber risks across the supply chain.
Conclusion
The oil and gas industry must embrace a holistic and risk-informed cybersecurity approach to effectively manage third-party risks. By adopting a unified framework, organizations can enhance their resilience, reduce vulnerabilities, and ensure the security of critical business functions and industrial systems. This report serves as a blueprint for improving third-party risk management and fosters collaboration within the industry and beyond.
试读结束,高清完整版pdf/doc/ppt,请点下载