On the Sharing of Cyber Security Information

On the Sharing of Cyber Security Information
复制标题

论网络安全信息共享

DOI:
--
复制
发表时间:
2015
期刊:
Critical Infrastructure Protection
影响因子:
--
通讯作者:
M. Klaver
M. Klaver
中科院分区:
--
文献类型:
--
作者:
E. Luiijf;M. Klaver

文献摘要

被引文献

相似文献

需要在公共和私营组织之间以及跨部门和边界共享网络安全信息,以提高态势感知,减少漏洞,管理风险并增强网络弹性。然而,信息共享的概念往往是一个广泛和多方面的概念。介绍网络安全信息共享的分析框架。关于信息交换元素的信息共享需求的分解被映射到一个网格,其垂直维度跨越战略/政策、战术和操作/技术级别,其水平维度跨越事件响应周期。该框架促进就可与其他实体共享的网络安全信息类型以及信息共享的条款和条件进行组织和法律讨论。此外,该框架还有助于确定现有信息交换标准中缺少的重要方面。
The sharing of cyber security information between organizations, both public and private, and across sectors and borders is required to increase situational awareness, reduce vulnerabilities, manage risk and enhance cyber resilience. However, the notion of information sharing often is a broad and multi-faceted concept. This chapter describes an analytic framework for sharing cyber security information. A decomposition of the information sharing needs with regard to information exchange elements is mapped to a grid whose vertical dimension spans the strategic/policy, tactical and operational/technical levels and whose horizontal dimension spans the incident response cycle. The framework facilitates organizational and legal discussions about the types of cyber security information that can be shared with other entities along with the terms and conditions of information sharing. Moreover, the framework helps identify important aspects that are missing in existing information exchange standards.