2018年-FSB全球金融稳定委员会_Public_responses_to_the_Cyber_Lexicon_Consultative_Document_6页_251kb
报告摘要
ACLI Comment on FSB Cyber Lexicon Consultative Document
Core Content
The American Council of Insurance Insurers (ACLI) submitted comments on the Financial Stability Board (FSB) Cyber Lexicon Consultative Document, offering suggestions for modifications, additions, and deletions to enhance the clarity, coherence, and practicality of the lexicon. ACLI represents 290 U.S. insurance companies, accounting for 95% of the industry's assets, and is focused on protecting customers' personal information and IT systems through effective risk-based, flexible, and workable cybersecurity frameworks.
Main Views
ACLI supports the FSB's goal of creating a cross-sector understanding of cyber security and resilience terminology. However, they believe that the current definitions in the Lexicon are too broad or ambiguous, which could lead to misinterpretation and hinder the effectiveness of the lexicon.
Definitions for Modification
- Asset: ACLI suggests a narrower definition that focuses on electronic information resources and excludes intangible information to avoid subjectivity. They propose using the definition from the NAIC Data Security Model Law and New York State's Cybersecurity Requirements for Financial Services Companies.
- Availability: ACLI recommends using the definition adapted from ISO and NIST, which emphasizes enabling timely and reliable access to authorized users.
- Confidentiality: They suggest replacing the current definition with the NIST definition to better clarify the concept of preserving authorized restrictions on information access.
- Cyber Event and Cyber Incident: ACLI argues that the current definitions are broader than those from NIST. They recommend aligning with NIST definitions to distinguish between potential and actual impacts. If not modified, they suggest updating related terms like "cyber risk," "cyber threat," "detect," "recover," and "respond" to refer to "cyber incident."
- Cyber Resilience: ACLI proposes a definition based on the CERT Glossary, emphasizing the ability to continue operations despite actual or threatened disruptions.
- Cyber Risk: They suggest a definition from the IAIS (2016) Issues Paper, which includes risks from electronic data use, transmission, and related liabilities.
- Cyber Threat: ACLI recommends a definition that focuses on circumstances or incidents with the potential to exploit vulnerabilities, leading to a loss of confidentiality, integrity, or availability.
Definitions for Addition
- Attack Vector or Threat Vector: ACLI suggests adding this term to describe the path or means by which a malicious actor can access a system to achieve a desired outcome.
- Control: They propose including a definition from the CERT Glossary, which outlines methods, policies, and procedures used to safeguard assets and protect information.
- Risk Management: ACLI recommends adding a definition from the CERT Glossary and NIST, which describes the continuous process of identifying, analyzing, and addressing cyber risks.
Definitions for Deletion
- Campaign: ACLI suggests removing this term as it is not commonly used in information security.
- Course of Action: This term is considered too technical and not aligned with the FSB's goals for the lexicon.
- Data Breach: They argue that this term is redundant with "cyber incident" and should be deleted.
Key Information
- ACLI emphasizes the importance of a risk-based, flexible, and scalable approach to cybersecurity terminology.
- The proposed changes aim to align the lexicon with existing standards like NIST, ISO, and NAIC, while reducing ambiguity and redundancy.
- ACLI is concerned about overly broad definitions that could hinder the clarity and effectiveness of the lexicon.
- The deletion of certain terms like "campaign," "course of action," and "data breach" is recommended to maintain consistency with the FSB's objectives.
试读结束,高清完整版pdf/doc/ppt,请点下载