世界经济论坛-工业物联网:安全和安全协议(英文)-2018.4-20页
报告摘要
Industrial Internet of Things (IIoT) Safety and Security Protocol Summary
Core Content
The Industrial Internet of Things (IIoT) is a rapidly growing field that integrates digital technologies with physical systems to transform industries and enhance operational efficiency. However, its growth has also introduced significant safety and security risks, which can lead to cyber-physical threats with wide-ranging impacts on public safety, infrastructure, and national security.
The World Economic Forum has established a Network of Experts to address these challenges and develop a protocol framework that aligns the responsibilities of all stakeholders in ensuring the security of IIoT systems. The protocol is designed to promote collective action, preventive security, and shared accountability among various entities, including manufacturers, service providers, governments, and the insurance industry.
Main Requirements and Opportunities
The protocol outlines several key requirements and opportunities to enhance IIoT security:
1. Broad Stakeholder Representation
- The Network includes participants from industry, international organizations, civil society, and academia.
- It emphasizes the need to involve public policy experts and IIoT users in discussions to ensure comprehensive understanding and informed decision-making.
2. Increased Awareness
- There is a need to raise awareness about IIoT security risks and their consequences.
- Entities deploying IIoT systems often lack expertise and understanding of security measures, leading to poor implementation and risk management.
3. Understanding Security Issues
- Entities deploying IIoT systems must be educated on security issues and best practices.
- Cybersecurity expertise is not typically a core competency for vendors or users, necessitating external guidance and support.
4. Establishing Incentive Structures
- The protocol advocates for education, secure design principles, insurance, and data security as key elements in creating a robust IIoT security framework.
- It highlights the importance of financial incentives and disincentives to drive compliance and responsible behavior.
- Examples include insurance-based premiums and penalties for non-compliance, which have been effective in other risk management contexts.
5. Public-Private Partnerships
- The protocol encourages national governments to engage in public-private partnerships to protect critical infrastructure.
- It references UN Security Council Resolution 2341, which promotes cooperation and information sharing to safeguard against terrorist attacks on infrastructure.
6. Supporting the Insurance Industry
- The insurance industry plays a crucial role in risk management and behavioral change.
- Insurers should use the protocol to evaluate insurability and differentiate premiums based on the security strength and reliability of IIoT implementations.
7. Learning from Historical Risk Management
- The protocol draws on historical examples of how insurance has been used to incentivize risk reduction in other sectors.
- These include electrical safety initiatives and payment card industry standards, which use incentives and penalties to promote best practices.
Protocol Objectives and Key Drivers
The main objective of the protocol is to improve the security of IIoT devices and systems and align user, manufacturer, and implementer behavior with public interest goals of safety and security.
- The Protocol aims to leverage insurance programs, standards, and governance structures to create incentives and realign demand/supply-side economics.
- It promotes active hardening processes and proven penetration, configuration, and compliance techniques to ensure robust security practices.
- The Protocol is intended to serve as a benchmark for IIoT system deployments and influence consumer IoT security practices.
Key Areas for Implementation
The protocol sets baseline conditions for insurability and participation in differentiated premium programs, focusing on three core areas:
A. Line of Business IIoT Device Safeguards
- Risk-assessment models: Identify and score digital and physical assets, threat agents, and vulnerabilities.
- Segmentation: Logically isolate sub-systems based on security requirements.
- Device integrity and availability: Ensure devices maintain integrity, availability, and confidentiality.
- Encryption: Use current, accepted protocols to secure data in transit and at rest.
- Patches and updating: Implement mechanisms for software updates and rollbacks.
- Privacy: Encrypt all personally identifiable data.
- Interoperability: Use standard protocols for communication.
- Software development lifecycle: Ensure all software undergoes rigorous testing and threat modeling.
- Root of trust: Establish trusted communication paths and zones.
- Vulnerability disclosures: Implement coordinated disclosure processes for external vulnerabilities.
B. Internal Governance and Risk Management
- Entities must demonstrate adequate internal governance and risk management mechanisms.
- These should include executive oversight, annual reviews, and audit processes.
C. Record-Keeping and Metrics
- Entities should maintain record-keeping systems and metrics to track and assess IIoT security performance.
Target Audience
The Protocol is targeted at three main groups:
- The financial sector, including the insurance industry.
- Companies, governments, and other entities operating IIoT systems as end-users.
- National governments and international governance bodies focused on protecting critical infrastructure.
Conclusion
The IIoT Safety and Security Protocol aims to enhance the security of IIoT systems through collective action, incentive structures, and risk management frameworks. It emphasizes the role of insurance in promoting security-enhancing behavior and preventing cyber-physical threats. By aligning stakeholder responsibilities and implementing best practices, the protocol seeks to ensure the reliability and safety of IIoT in the interconnected digital world.
试读结束,高清完整版pdf/doc/ppt,请点下载