世界经济论坛-网络弹性:公私合作手册(英文)-2018.1-72页-6mb
报告摘要
Cyber Resilience Playbook for Public-Private Collaboration Summary
Core Content
This document, Cyber Resilience: Playbook for Public-Private Collaboration, is a comprehensive guide aimed at fostering collaboration between the public and private sectors to enhance cybersecurity resilience. It was developed in partnership with The Boston Consulting Group and is part of the World Economic Forum's System Initiative on Shaping the Future of the Digital Economy and Society.
The report outlines a framework for understanding and addressing cybersecurity policy issues, emphasizing the need for a structured and collaborative approach. It provides a Reference Architecture and a set of Policy Models to help leaders navigate the complex landscape of cybersecurity.
Main Viewpoints
- Cybersecurity is a shared responsibility: Both public and private sectors have critical roles in ensuring cybersecurity, and effective collaboration is essential to mitigate risks.
- Policy-making is complex and interdependent: Cybersecurity policy topics are not isolated; they are interconnected, and decisions in one area can affect others.
- Balancing values is crucial: Policies must consider trade-offs between security, privacy, economic value, accountability, and fairness.
- International cooperation is necessary: Cybersecurity issues often transcend national borders, requiring coordinated and symmetric international responses.
Key Information
1. Introduction
- Cybersecurity is a growing concern in the Fourth Industrial Revolution, where the world is increasingly networked and digitized.
- States and organizations have an obligation to secure their digital environments, but this requires collaboration across sectors.
- The document serves as a tool for public and private leaders to build institutions, frameworks, and policies that support cybersecurity resilience.
2. Using the Playbook
- The Playbook is structured into two main sections: Reference Architecture and Cyber Policy Models.
- Reference Architecture provides an overview of 14 key policy topics and their interdependencies.
- Policy Models offer a structured approach to understanding specific cybersecurity topics and their associated trade-offs.
3. Reference Architecture for Public-Private Collaboration
- The 14 key policy topics include:
- Research, data, and intelligence sharing
- Zero-days
- Vulnerability liability
- Attribution
- Botnet disruption
- Monitoring
- Assigning national information security roles
- Encryption
- Cross-border data flows
- Notification requirements
- Duty of assistance
- Active defence
- Liability thresholds
- Cyberinsurance
- These topics are interconnected, and policies must be considered within this broader context.
4.1 Zero-days
- Definition: A zero-day vulnerability is an unknown software weakness that can be exploited before a patch is available.
- Policy Model:
- The life cycle of a zero-day includes introduction, discovery, and exploitation.
- Governments and private actors debate the use of zero-day exploits, with two main axes of policy: involvement in the zero-day market and disclosure.
- Governments may choose to stockpile or disclose vulnerabilities, depending on their strategic interests.
- The U.S. uses the "vulnerabilities equities process" to decide on disclosure, while other countries may adopt different approaches.
- Case Study: Google, Project Zero:
- Google actively discovers and discloses zero-day vulnerabilities to promote security.
- It uses a time-bound disclosure policy to incentivize vendors to develop patches quickly.
- This approach improves security by reducing the attack surface and limiting the exploitation of vulnerabilities.
4.2 Vulnerability Liability
- Definitions:
- Known vulnerability: A vulnerability that has been disclosed and has documented mitigation methods.
- End-of-life: A product no longer receiving updates or support.
- Open source software: Software with accessible source code and licensing requirements.
- Closed source software: Proprietary software with limited access to source code.
- Software-as-a-service (SaaS): Software hosted and maintained by a provider for users over the internet.
- Policy Model:
- Traditionally, software vendors have avoided liability for damages caused by vulnerabilities.
- The policy must address who is responsible for securing vulnerabilities and how liability shifts as products reach end-of-life.
- This involves considering the accountability of both public and private sectors in managing vulnerabilities.
Key Themes
- Clear Policy Scope: The roles and responsibilities of both sectors must be clearly defined.
- Legal Ambiguity: The scope of permissible activities for security practitioners is often unclear.
- International Impact: Policies in one country can have significant implications for others.
- Compliance vs. Resilience: Compliance with regulations may not always enhance cyber resilience.
- Preventive Measures: Investing in preventive actions can reduce the need for contentious trade-offs.
Connecting Policy to Values
- The document emphasizes the importance of balancing key values:
- Security: Can be improved through both offensive and defensive strategies.
- Privacy: May be compromised in offensive approaches.
- Economic Value: Security improvements can reduce damages and intangible costs.
- Accountability: The sharing of vulnerabilities affects the accountability of both sectors.
- Fairness: Ensuring equitable treatment and response in cybersecurity policy.
Conclusion
This Playbook is a foundational document for fostering collaboration and shared understanding in cybersecurity policy-making. It encourages leaders to move beyond polarized debates and adopt a more nuanced, values-based approach to cybersecurity. The document is intended to serve as a common language and framework for discussing the complex and interdependent nature of cybersecurity policy across the public and private sectors.
试读结束,高清完整版pdf/doc/ppt,请点下载