2018年-ECB欧洲央行_TIBER-EU_Framework_-_Services_Procurement_Guidelines_39页_625kb
报告摘要
TIBER-EU Framework: Services Procurement Guidelines Summary
Core Content
The TIBER-EU Framework is a structured approach for European and national authorities to test and enhance the resilience of financial entities against sophisticated cyber attacks. It is implemented through controlled, intelligence-led red team (RT) tests that simulate the tactics, techniques, and procedures (TTPs) of real threat actors. These tests are designed to evaluate an entity's protection, detection, and response capabilities.
To ensure the effectiveness and safety of these tests, the Services Procurement Guidelines provide detailed requirements and standards for selecting and engaging threat intelligence (TI) providers and red team (RT) providers. These guidelines are an integral part of the TIBER-EU Framework and are intended to help entities and authorities manage risks and ensure compliance with relevant standards.
Main Points
1. Purpose of the Guidelines
- To define the requirements and standards for TI and RT providers.
- To offer guiding principles and selection criteria for entities when procuring services.
- To provide checklists and questions to assist in the due diligence and procurement process.
2. Target Audience
- Authorities responsible for adopting and managing the TIBER-EU Framework.
- Entities looking to conduct TIBER-EU tests.
- TI and RT providers offering services under the TIBER-EU Framework.
- Accreditation and certification providers.
3. Multinational Entities
- Multinational entities must consider the requirements of other jurisdictions when conducting TIBER-EU tests.
- They should liaise with all relevant authorities to ensure compliance with their specific procurement and operational standards.
- The TIBER-EU Framework is a minimum standard and may not cover all local requirements.
4. Procurement Agreements
- Entities may have agreements with providers to streamline the procurement process.
- These agreements should still ensure that providers meet the standards outlined in the Guidelines.
- Entities should consult with the relevant TIBER Cyber Teams (TCTs) for further clarification.
Key Requirements for Threat Intelligence Providers
3.3 TI Provider Requirements
| Who | Requirements |
|---|---|
| TI Provider (at company level) | - At least three references from previous threat intelligence-led red team tests.<br>- Adequate indemnity insurance for activities not covered in the contract. |
| Threat Intelligence Manager | - Lead and oversight of TI provider activities.<br>- At least five years of threat intelligence experience, including three years in the financial services industry.<br>- Up-to-date CV and three references.<br>- Background checks (minimum standard, enhanced as required by national authorities).<br>- Ideally, hold recognised qualifications and certifications (see Annex 1). |
| Threat Intelligence Team Members | - At least two years of threat intelligence experience per member.<br>- Up-to-date CVs provided to the entity.<br>- Multidisciplinary skills including OSINT, HUMINT, and geopolitical knowledge.<br>- Background checks (minimum standard, enhanced as required by national authorities).<br>- Ideally, hold recognised qualifications and certifications (see Annex 1).<br>- Ideally, have experience in delivering threat intelligence for red team tests. |
Guiding Principles for Selecting TI Providers
3.4 Guiding Principles and Selection Criteria
-
Reputation, History, and Ethics:
- TI providers should have a strong reputation and ethical standards.
- They must demonstrate knowledge and expertise in threat intelligence and the financial sector.
- Ethical conduct is critical, including adherence to professional codes of conduct like the Code of Conduct for Ethical Security Testers or OSIRA Code of Conduct.
-
Governance, Security, and Risk Management:
- TI providers must have a robust Information Security Management System (ISMS).
- They should have a clear governance structure and processes that are effectively implemented and continuously monitored.
- The provider must ensure the security and confidentiality of the entity's data, including that of third-party suppliers.
-
Methodology:
- TI providers should have well-defined methodologies for collecting and analysing threat intelligence.
- These methodologies should be transparent, flexible, and capable of producing high-quality outputs for red team tests.
- They must be able to collect, source, and process information from a variety of data sources, including public and private forums, media, and social platforms.
Critical Characteristics of TI Collection
| Characteristic | Explanation |
|---|---|
| Breadth of Sources | The number of unique information items collected indicates the provider's capability. |
| Depth of Sources | Providers should be able to access all content from sources where lawful and appropriate. |
| Language Support | TI providers must support the language(s) relevant to the test, especially for local implementations. |
| Timeliness of Collection | Providers must be able to process and analyse data in real-time, especially from dynamic sources like social media. |
| Types of Intelligence | Providers using both OSINT and HUMINT are better suited for covert threat analysis. |
| Intelligence-Gathering Process | The process must include review, operations management, and quality management. |
| Threat Intelligence Analysis | Providers must use a range of techniques to produce actionable and realistic test scenarios. |
Conclusion
The Services Procurement Guidelines for TIBER-EU ensure that TI and RT providers are selected based on high standards of expertise, experience, and ethical conduct. These guidelines help entities and authorities conduct controlled, effective, and secure red team tests, which are essential for improving cyber resilience. Entities are encouraged to engage in thorough due diligence, and where possible, to use TIBER-EU accredited and certified providers to ensure compliance and quality. The TIBER-EU Knowledge Centre will monitor and update the guidelines as needed to reflect evolving standards and market practices.
试读结束,高清完整版pdf/doc/ppt,请点下载