欧洲政策研究中心-建立美欧跨大西洋网络安全的共同基础:波罗的海方针(英)-2021.8-22页_2mb
报告摘要
BUILDING COMMON GROUND IN TRANSATLANTIC CYBERSECURITY: A Baltic Approach
Core Content
This policy brief discusses the growing challenges in transatlantic cybersecurity cooperation, driven by divergences in data governance frameworks between the United States and the European Union. It outlines the need for a more integrated and cooperative approach to cybersecurity, emphasizing the importance of harmonizing data architecture, protection regimes, law enforcement cooperation, and cyber interventionist capacities.
Main Points
- Cybersecurity as a Priority: As sectors become increasingly data-dependent, cybersecurity threats are expanding in scope and impact, affecting critical infrastructure, services, and even national stability.
- Divergent Data Governance: The U.S. and EU have fundamentally different approaches to data governance, with the U.S. focusing on a market-based model centered on data ownership and the EU promoting a rights-based, harmonized framework.
- Cybersecurity Gaps: These differences in governance create interoperability issues, increasing cybersecurity risks and limiting the ability of the transatlantic alliance to effectively counter threats.
- Baltic Approach: A flexible, bottom-up model that integrates all relevant stakeholders (public, private, military, and civilian) into a unified forum for cybersecurity information sharing and cooperation.
- Recommendations: The brief proposes several strategies to improve transatlantic cybersecurity cooperation, including the establishment of a shared international cybersecurity council, enhancing threat information sharing through the U.S.-EU Trade and Technology Council, and confluencing civilian and military cybersecurity expertise via the EU's Joint Cyber Unit.
Key Information
Data Architecture
- The U.S. has a decentralized and siloed public sector data stewardship system, while the EU is building a centralized, harmonized data infrastructure through the European Cloud Initiative and GAIA-X.
- The EU's data pools and cloud initiatives aim to enhance digital sovereignty, while the U.S. lacks a similar centralized system.
- U.S. companies operating in the EU must adapt to EU data standards and potentially share data with EU data pools.
Data Protection
- The U.S. has a patchwork of data protection rules, with enforcement by the Federal Trade Commission and self-regulation, whereas the EU enforces strict, uniform data protection laws under the GDPR.
- The EU-US Privacy Shield and Safe Harbor have been invalidated by the CJEU, leading to the use of Standard Contractual Clauses (SCCs) for data transfers.
- SCCs require compliance with higher cybersecurity standards than those set by the NIST Cybersecurity Framework.
Law Enforcement Cooperation
- Cross-border digital information sharing is essential for law enforcement but is hindered by differences in data governance.
- The U.S. CLOUD Act allows the government to access data stored abroad, while the EU relies on MLATs and GDPR to ensure data protection.
- The EU's E-evidence package aims to enable direct cooperation with service providers, reducing reliance on bilateral agreements.
Cyberwarfare
- The U.S. engages in offensive cyber operations to disrupt adversarial activities, while the EU focuses on defensive cyber diplomacy and sanctions.
- The EU's NIS Directive mandates cybersecurity measures and incident reporting for essential services, whereas the U.S. has a voluntary framework under the NIST Cybersecurity Framework.
- The lack of standardized intelligence exchange channels between the EU and U.S. leads to different risk models and reduced collective threat prevention capacity.
Cybersecurity Gaps
- CERTs in the EU vary significantly in structure and function, often based on trust and limited interoperability.
- The NIS Directive 2 expands reporting and security requirements, increasing the disparity in risk assessments across the transatlantic.
- NATO's dual-use doctrine highlights the need for better coordination between civilian and military cybersecurity, especially in areas like 5G security.
Recommendations
- Establish a National Cybersecurity Council for Critical Functions: Create a shared international council between the U.S. and EU to coordinate cybersecurity for transatlantic critical functions.
- Enhance Threat Information Sharing via the U.S.-EU Trade and Technology Council: Use the council’s working groups to develop a unified threat information sharing mechanism.
- Conflate Civilian and Military Cybersecurity Experience: Implement the EU's Joint Cyber Unit to integrate civilian and military cybersecurity authorities, mirroring the U.S. Cyber Unified Coordination Group.
Conclusion
The Baltic approach offers a model for integrated cybersecurity governance that could help bridge the gap between the U.S. and EU. By fostering collaboration across sectors and promoting a shared understanding of cybersecurity threats and responses, the transatlantic alliance can enhance its collective resilience in an increasingly digital world.
试读结束,高清完整版pdf/doc/ppt,请点下载