战略与国际研究中心-Cybersecurity-Two-Years-Later_22页_1mb
报告摘要
Cybersecurity Two Years Later - Summary
Core Content
This report, published by the Center for Strategic and International Studies (CSIS) in January 2011, is a follow-up to their 2008 report Securing Cyberspace for the 44th Presidency. It evaluates the progress made in cybersecurity policy over the past two years and outlines key areas where further action is needed. The report emphasizes the urgency of securing cyberspace as a critical national security and economic issue, and highlights the challenges of developing a comprehensive, effective strategy.
Main Viewpoints
- Cybersecurity as a National Priority: Cybersecurity is now recognized as a critical challenge for national security, yet the U.S. remains unprepared to address it effectively.
- Need for a Coherent Strategy: The U.S. lacks a unified national cybersecurity strategy and has not adequately addressed the risks posed by cyber threats.
- Private Sector Reliance is Inadequate: Relying on the private sector alone to secure networks is insufficient, especially against nation-state actors and advanced cybercriminals.
- Global Cyber Governance Challenges: The U.S. must lead in establishing norms, consequences, and cooperation in international cyber policy, as other nations seek to assert control over cyberspace.
- Regulation and Coordination are Necessary: Flexible, industry-cooperative regulations and a centralized coordinating body are essential for improving cybersecurity.
Key Information
I. Introduction
- Cybersecurity has become a critical national security challenge, but progress has been slow.
- Major cyber incidents in 2010, such as the Google hack and the Stuxnet worm, highlighted the vulnerability of the U.S. digital infrastructure.
- The U.S. must develop a more robust and coordinated approach to cybersecurity, as the Internet has grown to become a global, critical infrastructure.
II. The State of Nature in Cyberspace
- The Internet was not designed for global security, and its openness has led to increased risks.
- Cyber threats such as espionage and cybercrime are more prevalent than cyber warfare or terrorism.
- Advanced cybercriminals and nation-states have capabilities that rival those of intelligence agencies.
- The U.S. has not yet developed effective defenses against these threats, and many important cybersecurity measures have been delayed.
III. The Policy Context
- The U.S. has adopted a voluntary, public-private partnership model for cybersecurity, which has proven inadequate.
- The 2003 National Strategy to Secure Cyberspace and the 2008 Comprehensive National Cybersecurity Initiative emphasized information sharing and cooperation, but these have not led to significant progress.
- There is strong resistance to regulation due to the "Internet Wild West" ideology and concerns about stifling innovation.
- The market alone cannot ensure cybersecurity, especially in critical infrastructure, where government intervention is necessary.
IV. Ten Key Areas for Progress
-
Coherent Organization and Leadership:
- A unified national cybersecurity strategy is needed.
- The administration has taken some steps, such as creating a cybersecurity coordinator, but more is required.
- The White House Office of Management and Budget (OMB) has made progress in improving federal cybersecurity standards.
-
Clear Authority for Critical Infrastructure:
- The U.S. needs stronger regulatory frameworks to ensure cybersecurity in critical sectors.
- Legislation that includes mandatory improvements in authentication and security standards is essential.
- The administration and Congress should prioritize passing effective cybersecurity laws.
-
Foreign Policy for Cybersecurity:
- The U.S. must use all tools of power—diplomatic, military, and economic—to shape global cyber norms.
- International cooperation is crucial, as other nations seek to exert control over cyberspace.
- The U.S. should lead in developing a global framework for cybersecurity governance and enforcement.
-
Enhanced Use of Intelligence and Military Capabilities:
- The Department of Defense (DOD) has made cybersecurity a priority with the creation of U.S. Cyber Command.
- Active Defense initiatives are being developed, but concerns about privacy and legal authority remain.
- The use of military capabilities in cyber defense requires clear doctrine and policy guidance.
Conclusion
- The U.S. must move beyond the "voluntary" model and develop a more comprehensive, proactive cybersecurity strategy.
- Cybersecurity is not just a technical issue but a strategic and policy challenge that requires leadership, coordination, and international cooperation.
- The report calls for a new, more robust national cybersecurity framework that includes regulation, stronger federal leadership, and a clear vision for global cyber governance.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载