2018年-FSB全球金融稳定委员会_Cyber_Lexicon_Consultative_Document_21页_423kb
报告摘要
Cyber Lexicon Summary
Core Content
The Cyber Lexicon is a document published by the Financial Stability Board (FSB) in July 2018, aimed at creating a common understanding of cyber security and cyber resilience terminology across the financial sector and international bodies. It was developed in response to the Baden-Baden Communiqué from the March 2017 G20 meeting, which highlighted the growing threat of malicious use of Information and Communication Technologies (ICT) to financial systems. The FSB initiated a stocktake of existing regulations and supervisory practices in G20 jurisdictions and internationally, and based on that, a draft lexicon was created to support cross-border cooperation and consistency in terminology.
The lexicon is not legally binding and is intended to be a supportive tool for FSB, standard-setting bodies (SSBs), financial sector authorities, and private participants. It is not meant for legal interpretation or private contracts, but rather to assist in the development of regulatory, supervisory, and industry practices related to cyber security and cyber resilience.
Main Objectives
- Promote common understanding of cyber security and cyber resilience terminology across the financial sector.
- Support assessments and monitoring of financial stability risks related to cyber incidents.
- Facilitate appropriate information sharing between public and private sector participants.
- Enhance guidance from FSB and SSBs on effective cyber practices, reducing the risk of duplication or conflict in regulations.
Key Points in Development
3.1 Process for Developing the Draft Lexicon
- A working group of experts, chaired by the U.S. Federal Reserve Board, was formed to develop the lexicon.
- Members were selected based on expertise in cyber security and supervision and representation across FSB member jurisdictions and financial sectors.
- The working group engaged with public officials, SSBs, and industry organizations such as ISO, ISACA, SANS, and NIST to draw on existing definitions and standards.
- The Standing Committee on Supervisory and Regulatory Cooperation and FSB full membership also contributed to the draft.
3.2 Selection of Terms
- The lexicon focuses on core terms relevant to cyber security and cyber resilience in the financial sector.
- Technical ICT terms are generally excluded to ensure the lexicon remains accessible and focused on the needs of financial sector participants.
- General business and regulatory terms are also excluded unless they are directly relevant to cyber security and cyber resilience.
- Some terms included may have broader meanings, but the definitions provided are tailored to the cyber security and cyber resilience context.
3.3 Criteria for Definitions
- Reliance on existing sources: Definitions are drawn from established standards and guidelines, such as those from ISO, NIST, CPMI-IOSCO, and ISACA.
- Comprehensive definitions: Definitions are designed to capture all essential elements of the term in the context of cyber security and resilience.
- Plain language: Definitions are written in clear, concise language to ensure accessibility and ease of understanding.
Key Information
- The FSB is tasked with developing and promoting effective regulatory and supervisory policies in the financial sector.
- Cyber incidents pose a serious threat to financial systems, as evidenced by high-profile attacks like the Bangladesh Bank attack (2016), WannaCry ransomware (2017), and Equifax hack (2017).
- The lexicon is a collaborative effort involving both public and private sector stakeholders.
- The draft lexicon was published for public consultation and is expected to be finalized for delivery to the G20 Summit in Buenos Aires in November 2018.
- Comments are invited by 20 August 2018 via email to fsb@fsb.org.
Annex: Draft Cyber Lexicon
The Annex provides a list of key terms and their definitions, with sources cited for each. Some of the terms include:
- Access Control: Ensuring access to assets is authorized and restricted based on business and security requirements.
- Authentication: Providing assurance that a claimed characteristic of an entity is correct.
- Confidentiality: Ensuring information is not disclosed to unauthorized individuals or processes.
- Cyber Security: Preservation of confidentiality, integrity, and availability of information through the cyber medium.
- Cyber Resilience: The ability to anticipate, adapt to, withstand, contain, and rapidly recover from a cyber incident.
- Cyber Risk: The combination of the probability of cyber events and their consequences.
- Data Breach: Compromise of security leading to unauthorized access, disclosure, or alteration of protected data.
- Defence-in-Depth: A security strategy that uses multiple layers of protection.
- Multi-Factor Authentication: Authentication using two or more factors (knowledge, possession, biometric).
- Incident Response Team (IRT): A team responsible for handling cyber incidents during their lifecycle.
- Indicators of Compromise (IoCs): Evidence of an intrusion that can be identified in an information system.
- Continuous Monitoring: Maintaining ongoing awareness of information security and threats.
- Patch Management: Systematic process for identifying, deploying, and verifying software updates.
- Penetration Testing: Method for evaluating vulnerabilities in information systems.
Conclusion
The Cyber Lexicon is a foundational tool for enhancing cross-border cooperation and consistency in terminology within the financial sector. It is designed to support regulatory, supervisory, and industry efforts to improve cyber security and resilience. The FSB encourages public feedback to refine the lexicon and ensure it remains relevant and useful as the field evolves.
试读结束,高清完整版pdf/doc/ppt,请点下载