战略与国际研究中心-Workshop-Report_-ISCN_6页_821kb
报告摘要
ISCN-CSIS Washington Workshop 2016 Summary: Nuclear Security Collaboration Between CoEs and Civil Society
Introduction
On July 21, 2016, the Center for Strategic and International Studies (CSIS) Proliferation Prevention Program (PPP) and the Japanese Atomic Energy Agency (JAEA) Integrated Support Center for Nuclear Nonproliferation and Nuclear Security (ISCN) co-hosted a workshop in Washington, D.C., focusing on collaboration between Centers of Excellence (CoEs) and civil society in enhancing nuclear security, particularly in response to cyber threats. This event followed previous CSIS-JAEA meetings and aimed to build on progress made in regional and global cooperation since the Nuclear Security Summits.
Key Areas of Success
- Improved regional and bilateral cooperation: Training initiatives have enhanced collaboration among CoEs and industry partners.
- Enhanced global coordination: The International Network for Nuclear Security Training and Support Centers (NSSC) has improved global coordination.
- Government and industry collaboration: The U.S. government, particularly the Nuclear Regulatory Commission (NRC), works closely with the nuclear industry to promote cybersecurity standards.
Session I: Cyber Security
U.S. Approach to Nuclear Cybersecurity
- The U.S. nuclear industry has been proactive in cybersecurity, with efforts beginning before 9/11, especially in response to the Y2K issue.
- The NRC issued cybersecurity regulations in 2009, and the industry began implementing key measures in 2012.
- Full implementation of cybersecurity measures across all nuclear facilities is expected by 2017.
- Design-basis threats (DBTs) are regularly updated to reflect evolving cyber threats.
- While all employees receive some training, IT staff, engineers, and operators are primarily responsible for daily cybersecurity implementation.
- Air-gapped systems are not entirely secure due to the need for temporary connectivity during maintenance or updates.
Japan's Cybersecurity Efforts
- Japan updated its cybersecurity regulations in 2012 to align with IAEA recommendations.
- A lack of trained personnel who understand both IT security and nuclear control systems is a major challenge.
- Physical security personnel often implement cybersecurity measures in Japan.
- Cybersecurity awareness is less widespread in Japan compared to the U.S., but the country has started addressing this with training courses since 2014.
- Training costs are high due to the complexity of nuclear cybersecurity.
Russia's Cybersecurity Landscape
- Russia's cybersecurity regulations initially prioritized confidentiality over integrity and availability.
- Several executive orders have been issued in the last five years, but federal laws are needed for enforcement.
- The lack of comprehensive legislation has led to incomplete vendor oversight and limited cybersecurity by design.
- Vendor source code transparency was raised as a potential measure to prevent covert programs, though it is seen as burdensome and costly.
- NTI's Nuclear Security Index highlights that nearly half of the 47 countries surveyed lack national-level regulations to protect against cyberattacks.
Challenges and Opportunities
- Cybersecurity efforts are piecemeal and struggle to keep pace with evolving threats.
- International cooperation is hindered by the desire to keep countermeasures secret.
- New nuclear countries are particularly vulnerable and lack the capacity to address cyber threats.
- There is a need for tabletop exercises and international response teams to improve preparedness and coordination.
- A program similar to the U.S. NEST could provide valuable support in responding to cyberattacks on nuclear facilities.
Session II: Building Public Confidence
Public Outreach and Communication
- The ISCN has limited experience in public outreach due to its focus on industry professionals.
- There is a need to clarify who should lead public outreach, what topics to address, and what information to share.
- High-profile events like the Nuclear Security Summits may give the public a false sense of security.
- Cyber threats are often under-discussed even among experts, such as nuclear engineers.
- IAEA's 2015 conference on computer security highlighted the need for broader collaboration across sectors.
Role of Civil Society
- Civil society can play a vital role in communicating risks to the public and acting as a watchdog for the nuclear industry.
- Organizations like the Union of Concerned Scientists have access to classified information and could provide assessments of countries' cybersecurity readiness.
- Ensuring well-informed experts is essential for guiding the public during a crisis.
- Workshops and training programs that bring together academics, policymakers, civil society, industry officials, and emergency responders can foster cross-sector collaboration and knowledge sharing.
Conclusion
The workshop emphasized the importance of collaboration between CoEs and civil society in addressing the growing cybersecurity risks to nuclear facilities. While progress has been made in regional and global cooperation, significant challenges remain in regulatory frameworks, expertise, and public communication. Strengthening international coordination, increasing awareness, and developing shared response mechanisms are critical steps toward improving nuclear security in the digital age.
试读结束,高清完整版pdf/doc/ppt,请点下载