世界经济论坛-网络弹性系统:安全可靠的金融科技-2020.7_37页_3mb
报告摘要
Summary of "Systems of Cyber Resilience: Secure and Trusted FinTech"
Core Content
This document outlines the World Economic Forum FinTech Cybersecurity Consortium's efforts to establish common cybersecurity standards for FinTech companies to enhance cyber resilience across the financial ecosystem. It emphasizes the need for a baseline framework that is scalable, achievable, and globally applicable, to ensure secure and trusted FinTech operations.
Main Views
- Cyber Risk is Systemic: Cyber threats are pervasive, affecting the entire financial ecosystem, which includes both established financial institutions and FinTechs.
- Modular Financial Services Increase Risk: The increasing modularization and distribution of financial services create more points of vulnerability and complicate risk management.
- Need for Common Standards: A common, globally accepted baseline of cybersecurity controls is essential to reduce the complexity and fragmentation of regulatory requirements for FinTechs.
- Collaboration is Key: Industry, government, and non-profit organizations must collaborate to define and implement effective cybersecurity controls and frameworks.
- Regulatory and Industry Roles: Governments should support industry efforts by endorsing and examining cybersecurity controls, while the private sector should define controls based on expertise and evolving threats.
- Adaptability is Crucial: Cybersecurity frameworks must be adaptable, business-driven, and threat-based rather than static and capability-driven.
Key Information
1. Cyber Resilience in Financial Ecosystems
- Cyber threats are among the most significant risks to society and the economy.
- FinTechs are a critical part of the financial ecosystem, providing innovative services that require secure and trusted operations.
- Cybersecurity maturity levels vary across organizations, making it difficult for FinTechs to align with the expectations of their partners and regulators.
- Effective cybersecurity reduces the impact of attacks, protects client assets, and maintains consumer trust.
2. Challenges for FinTechs
- Fragmented regulations across jurisdictions make it hard for FinTechs to meet compliance requirements and manage risk effectively.
- Limited resources and shortage of skilled expertise are significant barriers for FinTechs to implement robust security measures.
- Technical debt can arise if security is not prioritized early in product development, leading to costly and complex fixes later.
3. Consortium Recommendations
- Establish a common framework: A unified cybersecurity framework should be developed to provide a baseline for all FinTechs, with tiered requirements based on maturity, services, and location.
- Regularly update frameworks: Cybersecurity controls must evolve with the changing threat landscape, business models, and regulatory environments.
- Collaborative design: Cybersecurity controls should be defined in consultation with industry experts, governmental agencies, and civil society organizations.
- Public endorsement: Financial regulators should publicly endorse initiatives that improve cyber resilience to encourage adoption.
- Adaptability and scalability: Frameworks must be adaptable to different business needs and scalable across borders to support market expansion.
4. Regulatory Ecosystem
- International bodies such as the Bank of International Settlements (BIS), Committee on Payments and Market Infrastructures (CPMI-IOSCO), Financial Stability Board (FSB), and World Bank play a role in shaping global cybersecurity governance.
- Regulatory requirements are local, but financial services and cyber threats are global in nature.
- Supranational bodies like the European Central Bank help provide common standards for cyber risk management in certain regions.
5. Universal Cybersecurity Controls and Assessment
- A tiered approach to cybersecurity controls is recommended, similar to the structure of a Swiss chocolate bar.
- Tier 1 includes universal security essentials applicable to all FinTechs, such as data protection, access control, and incident response.
- Tier 2 includes industry-specific requirements, such as PCI DSS for payment services.
- Tier 3 includes specialized controls that reflect the maturity level and business model of a FinTech.
6. Criteria for Choosing Base-Level Frameworks
- Relevance and applicability across jurisdictions.
- Compliance with regulatory expectations.
- Support for business growth and market expansion.
- Alignment with international standards and best practices.
- Sustainability and adaptability to changing threats and technologies.
Conclusion
The FinTech Cybersecurity Consortium aims to simplify and rationalize cybersecurity requirements for FinTechs, enabling them to scale securely and build trust with partners and regulators. By promoting collaboration, common frameworks, and regulatory support, the Consortium seeks to improve the cyber resilience of the global financial system and support the sustainable growth of FinTech companies.
Appendix Notes
- Appendix 1 compares CIS Critical Security Controls (CSC 20) with base-level controls criteria.
- Appendix 2 outlines the Financial Services Cybersecurity Profile (FSC Profile) and its alignment with base-level controls.
- Appendix 3 highlights the role of public-private partnerships in enhancing cybersecurity and building resilience.
Contributors
- Matthew Blake – Head, Platform for Shaping the Future of Financial and Monetary Systems
- Daniel Dobrygowski – Head of Corporate Governance and Digital Trust, World Economic Forum
- Adrienne Allen – Director of Security GRC and Privacy, Coinbase
- Adam Sommer – Vice-President, Industry Standards at Mastercard
- Jim Maloney – Chief Security and Privacy Officer, Social Finance (SoFi)
- Sunil Seshadri – Senior Vice-President, Chief Information Security Officer, Visa
试读结束,高清完整版pdf/doc/ppt,请点下载