版權(quán)說(shuō)明:本文檔由用戶(hù)提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
Facilitating
GlobalInteroperability
ofCyber
Regulations
inthe
Electricity
SectorSYS
T
E
M
S
O
F
CY
B
E
R
R
E
S
I
L
I
E
N
C
E
:E
L
E
C
T
R
I
C
I
T
Y
I
N
I
T
I
A
T
I
V
EP
O
S
I
T
I
O
N
P
A
PE
RN
OV
E
M
B
E
R
20
23Images:GettyImagesContentsIntroduction341
Currentstateofaffairs2
Importanceofglobalregulatoryinteroperability3
10keythemesforglobalregulatoryinteroperability4
CommunitypositiononthekeythemesConclusion5678Contributors9Annex1:Relatedpublications11DisclaimerThisdocumentispublishedbytheWorldEconomicForumasacontributiontoaproject,insightareaorinteraction.The?ndings,interpretationsandconclusionsexpressedhereinarearesultofacollaborativeprocessfacilitatedandendorsedbytheWorldEconomicForumbutwhoseresultsdonotnecessarilyrepresenttheviewsoftheWorldEconomicForum,northeentiretyofitsMembers,Partnersorotherstakeholders.?2023WorldEconomicForum.Allrightsreserved.Nopartofthispublicationmaybereproducedortransmittedinanyformorbyanymeans,includingphotocopyingandrecording,orbyanyinformationstorageandretrievalsystem.FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector2November2023FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySectorIntroductionIntoday’s
interconnectedworld,theelectricitysectorstandsasacornerstoneofsocietalfunctioning,poweringindustries,homesandcriticalinfrastructure.Aspowersystemsgothroughrapiddigitaltransformation,thecriticallinkbetweencybersecurityandtheenergylandscapebecomesincreasinglyevident.Theneedforglobalinteroperabilityincyberregulationsintheelectricitysectorhasbecomeparamount.ThispositionpaperfromtheSystemsofCyberResilience:Electricity(SCRE)initiativeaimstoconsolidateacohesivestancefromtheelectricitysectoroncybersecurity.Itadvocatesforinteroperabilityamongnationstocultivateacybersecure,resilientandstandardizedapproacharoundtheworld.Byscrutinizingthecurrentlandscapeofcyberregulations,thepaperendeavourstotackleexistinggapsandcomplexitieswhileproposingcollectivepositionstostandardizecybersecuritypracticesacrossdiverseregulatoryenvironments.Itsobjectiveistochampioninternationalcooperation,mutualunderstandingandtheadoptionofcommonstandardstofortifytheelectricitysectoragainstemergingcyberthreatswhileencouraginginnovationandgrowth.Theevolutionoftechnologyhassigni?cantlyreshaped
theelectricityindustry,usheringinsmartergrids,integrationofrenewable
energyandimproved
operationalef?ciencies.
However,thisevolutionpresents
a
newsetofchallenges,particularlyinsafeguarding
theseintricatesystemsfrom
cyberthreats.
Theincreasinginterdependencies
amongpowersystemsacross
borders
andthegrowing
sophisticationofcyberattacksunderscore
theimportanceofaharmonized,globalapproach
tocybersecurityregulations
intheelectricitysector.Ultimately,thispositionpaperstrivestocontributetotheongoingdiscourseonharmonizationofregulationstonurtureasecure,interoperableandresilientglobalelectricityecosystem,ensuringareliableandsafeenergysupplyfortheworld’spopulationinanincreasinglydigitalizedworld.TheSystemsofCyberResilience:ElectricityInitiativeSince2018,theWorldEconomicForum’s
SystemsofCyberResilience:Electricity(SCRE)initiativehasbroughttogetherrepresentativesofover60electricityutilities,energyserviceproviders,regulatorybodiesandotherpertinentorganizationsworldwide.Theireffortsaimtoachievecooperationandfortifyacyberresilientelectricityecosystem.TheSCREstandsoutastheonlyglobalpublic-privatepartnershiptailoredfortheelectricityindustry,wherecybersecurityexpertscollaboratetoenhanceresilienceacrosstheelectricityecosystem.Itis
a
great
opportunityto
createa
collaborativeenvironment,focused
onincreasing
globalcyberresilience,
basedonthe
sharingof
information,on
thedevelopment
of
commoninitiatives,
onthede?nitionof
principles
andthe
alignmentaround
them
bythe
mainactorsof
our
industry.Jesús
Sánchez,
Headof
Global
Cybersecurity,NaturgyTheGlobalRegulationsWorkingGroupInSeptember2022,theSCREcommunityhadidenti?edglobalregulatoryinteroperabilityintheelectricitysectorasoneofitskeyfocusareas,andhadsetuptheGlobalRegulationsworkinggrouptowardsthisend.electricitysector,
markedbyfragmentation,inconsistencyandsporadiccon?icts.Theseregulatorybarriersimpedetheattainmentofglobalinteroperability,resultinginincreasedcosts,inef?cienciesandmissedopportunities.Resourcesaredivertedtoresolveregulatoryissuesratherthanimprovingcybersecurityposturesspeci?ctothesectoranditsvariousorganizations.TheworkinggroupaddressestheintricateglobalregulatorychallengesprevalentthroughouttheFacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector3Current
stateofaffairs1Regulatorsandgovernmentagenciesresponsibleforestablishingcybersecurityrequirements
invariousindustriesworldwideoftenadoptdifferentapproaches
totacklesimilarcybersecuritychallengesduetothelackofa
globalconsensus.Thisresults
incomplex,industry-agnostic,fragmented,inconsistentandoccasionallycon?ictingsetsofregulations.
Theseregulationsnotonlylackmutualinteroperability
butactivelyhinderit.Thedynamicnature
ofcybersecuritythreats
furthercompoundstheproblem
asregulators
frequently
tightenregulations
inresponse.
Thisforces
organizationstoallocatetheirlimitedresources
towards
complianceratherthanconcentratingonbolsteringtheircybersecuritydefences.Moreover,
there
isa
pressing
concerntoensure
thatregulatory
interoperability
doesnotcompromise
nationalsecurity.Nationsmuststrikea
balancebetweentheneedfora
collectivecybersecurityfront
andtheneedtoprotect
theirindividualinterests
andsecurity.Despitetheobstacles,solutionscanbefound.Initiativessuchasworkinggroups,internationalforumsandcollaborativeagreementscanplayapivotalroleinpromotingdialogueandestablishingrobustsystemstomonitor,
evaluateandupdateregulatoryframeworks.Thesemechanismsnotonlycontributetoamoresecureandresilientdigitallandscapebutalsofosterinnovationandgrowth.Manyregulatorsandgovernmentagencieshavebeguntorecognizetheneedforregulatoryharmonizationandmultipleeffortshavebeenputintopractice,suchastheEuropeanCommission’sCyberResilienceAct(CRA)andtheWhiteHouseOf?ceoftheNationalCyberDirector(ONCD)’srequestforinformation(RFI)oncybersecurityregulatoryharmonization.Achievingregulatory
interoperabilitymaypresentchallenges.Differencesincybersecuritystandards,legalsystemsandnationalprioritiesamongvariousjurisdictions
can
lead
to
con?icts
and
inconsistencies,makingitdif?culttoestablishandmaintaininteroperabilityovertime.Onenotablechallengeistheissueofdataprivacylaws,asdifferentcountrieshaveuniquedataprotection
regulations
tailoredtotheircultural,economicandpoliticallandscapes.Simultaneously,severalinternationaldialoguesaregoingonbetweenstates,suchastheEU-USCyberDialogue,US-JapanCyberDialogueandFrance-UnitedKingdomCyberDialogue,inadditiontoregulatoryreciprocityschemessuchastheEU-USDataPrivacyFramework,SingaporeCybersecurityLabellingSchemeandAPECCross-BorderPrivacyRules(CBPR)system.Asimilarchallengearisesinincidentreportinglaws.Forinstance,somecountriesmandatethereportingofalldatabreaches,regardlessoftheirseverity,whileothershavethresholdsforreportingbasedonthenumberofaffectedindividualsorthelevelofharm.Thesedifferencescancreatedif?cultiesinincidentresponseandinformationsharing,particularlyincaseswhereabreachspansmultiplejurisdictions.Creatingsynergyamongthesediverseregulationsisacomplexandintricateprocess,especiallygiventherapidpaceofdigitalinnovation.Thisdynamicenvironmentnecessitatesconstantupdatesandrevisionstoensuretheregulationsremainrelevantandeffective.Whiletheseeffortsareintherightdirection,theyarefarfromachievingglobalinteroperabilityandmuchworkremainstobedonebyboththepublicandprivatesectorstobuildamorecyberresilientelectricityecosystem.FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector4Importanceofglobalregulatoryinteroperability2Aligningcybersecurityregulationsgloballyensuresuniformcybersecuritypractices,enablingcompaniesoperatingacrossmultipleregionstoadheretoconsistentstandards.Harmonizationreducescomplexityandconfusion,simplifyingcomplianceefforts.
Moreover,
interoperabilityfostersenhancedcollaborationandinformationsharingamongvariousentitiesglobally,facilitatingjointeffortstocombatcyberthreatsandexchangebestpractices.bolsteringoverallcyberresilience.Aharmonizedregulatorylandscapefostersafairplaying?eld,encouraginginnovationandthedevelopmentofnewcybersecuritytechnologies,freefromvaryingcompliancerequirements.Inacyberincidentwithglobalimplications,uniformregulationsenableacoordinatedandef?cientresponseacrossmultiplejurisdictions,signi?cantlymitigatingtheimpactofsuchincidents.Giventheglobalspreadofsupplychains,beingabletorelyonsharedprevention,mitigation,informationsharingandincidentresponsepracticeswillleadtoamoresustainable,cyberresilientecosystemworldwide.Ultimately,regulatoryinteroperabilityforcybersecurityaroundtheworldisimperativetofosteramoresecuredigitalandphysicalenvironment.Itcanalignstandards,promotecollaboration,reducecostsandeffectivelymanageandrespondtocyberthreatsworldwide.Auni?edapproachtocybersecurityregulationsallowsforacomprehensiveunderstandingandmanagementofrisks,transcendingdifferentregionsintheelectricityindustry.Standardizingregulationsminimizesthecomplexityandcostsofcomplianceforglobalcorporations,eliminatingtheneedtonavigateamultitudeofdivergentregulations.Globalinteroperabilityalsoleadstomorerobustdefencemechanismsagainstcyberthreatsbyenablingstandardizedcybersecuritypractices,510keythemesforglobalregulatoryinteroperability3Afteranalysingmultipleregulations,thecommunityhasidenti?ed10keyglobalregulatorythemesforregulatorstoconsider.FIGURE1
KeythemesforfacilitatingglobalinteroperabilityofcyberregulationsComplianceandenforcementAdoptionofexistinginternationalstandardsDataprotectionandprivacy10keythemesforfacilitatingglobalinteroperabilityThird-partyriskmanagementInformationsharingofcyberregulationsRiskassessmentandmanagementIncidentresponseandreportingVulnerabilitydisclosureandmanagementInternalpoliciesandproceduresforcybersecurityhygienePenetrationtestingSource:SCREGlobalRegulationsworkinggroup.FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector6Communitypositiononthekeythemes4TheSCREGlobalRegulationsworkinggrouphasadoptedthefollowingpositionsonthe10keyglobalregulatorythemes:6.
Penetrationtesting:Globalcommitmenttoregularinternalpenetrationtesting,whichincludesoperationaltechnology(OT)penetrationtesting.Thisallowsforidentifyingandaddressingpotentialweaknessesinsystemsandinfrastructure,fortifyingdefencesagainstcyberthreats.1.
Complianceandenforcement:
Globalcommitmenttoprioritizecybersecuritybestpracticesovercompliance.Thisimpliesa
shiftinmindset.Insteadofmerely
meetingregulatoryrequirements,
thefocusisonprioritizing7.
Vulnerabilitydisclosureandmanagement:Globalcommitmenttosectorialvulnerabilitydisclosureamongclosedgroupsofsector-speci?c,pre-authorizedentities.Thiswouldfosterasecureenvironmentforinformationsharingwithinclosedgroups,allowingforproactiveresolutionofvulnerabilitieswithoutriskingwidespreadexposure.cybersecuritymeasures
andprotocols,
sometimesbeyondwhatismandated.Thisapproachemphasizesa
proactive
stanceinensuringa
highlevelofcybersecurityratherthanjustcheckingtheboxestocomplywithregulations.2.
Dataprotectionandprivacy:GlobalcommitmenttosupportdataprotectionandprivacyregulationssuchastheGeneralDataProtectionRegulation(GDPR)oftheEuropeanUnion(EU).Thiscommitmentindicatesarecognitionoftheimportanceofsafeguardingsensitiveinformation.Itsambitincludesdataprivacy,ensuringthecon?dentiality,integrityandavailabilityofdatawhilealigningwiththeprinciplesofprivacybydesignanddefault.8.
Riskassessmentandmanagement:Globalcommitmenttoapplyingriskassessmentmethodologyconsistentlyacrossinformationtechnologyandoperationaltechnologyenvironments.ApplyingconsistentriskassessmentmethodologyacrossITandOTenvironmentsensuresacomprehensiveunderstandingofpotentialrisks,allowingforbetter-informedandtimelydecision-makingregardingcybersecuritymatters.3.
Informationsharing:Globalcommitmenttocreateanduseacommoninformation-sharingprotocolandtaxonomyworldwide,andtosupporttherespectiveelectricityinformationsharingandanalysiscentres(ISACs).9.
Third-partyriskmanagement:
Globalcommitmentthateveryorganizationinthesupplychainmustconsiderandberesponsibleforthecybersecurityofitsscopeofwork.Thiswouldensure
a
comprehensive
approachtomanagingandmitigatingrisksassociatedwiththird-party
involvement,securingandembracingecosystem-wideresilience
intheelectricitysector.Establishingacommoninformation-sharingprotocolandtaxonomygloballyisvital.Itallowsforconsistentcommunicationandcollaborationamongvariousstakeholdersintheelectricitysector,
enhancingtheabilitytopromptlyidentifyandrespondtothreats.ThiscommitmentextendstosupportingISACs.10.
Adoptionofexistinginternationalstandardsversuscreationofunique,national(orregional)standards:
GlobalcommitmenttoadoptionofmatureexistinginternationalstandardssuchasISO27001andtheISA/IEC62443series.Adoptingexistinginternationalstandardsratherthancreatinguniqueregionalstandardswouldensurea
moreuniversallyacceptedandharmonizedapproachto4.
Incidentresponseandreporting:
Globalcommitmenttoadopta
commonandef?cientinternational
incidentreportingtaxonomyandrequirements.Thiscommitmentwouldensureastandardized
approachtoreportingcybersecurityincidents.Sucha
taxonomyfacilitatesa
betterandsharedunderstandingofthenatureandimpactofincidents,enablinga
coordinatedandtimelyresponsebothwithinandacross
borders.cybersecuritypractices,leveragingestablishedbestpractices.Thesestandardsshouldbeupdatedwhenneededtoallowfora
harmonizedapproachtoglobalregulationsinsteadoffrequentchangestryingtoaccountforevolvingtechnologiesandthreats.5.
Cybersecurityhygieneinternalpoliciesandprocedures:Globalcommitmenttoestablishbasiccyberhygieneprinciplesspeci?ctotheelectricitysector.
Thiscommitmentwouldprovideforafoundationallevelofsecurityacrossalloperations,reducingvulnerabilities,enhancingoverallresilienceandpromotingacybersecurityculture.FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector7ConclusionThesecollectivecommitmentshelpregulatorsandotherstakeholdersintheelectricitysectortoshareacommonvisionandunderstandwhattheelectricitysectordeemsasimportanttobecyberresilient.Together,
theyembodythedirectionthattheglobalcommunityisheadingtowards.Additionally,theadoptionofinternationalstandardsandthepromotionofsecureinformation-sharingenvironmentsplayacriticalrole.Theseactionsencouragecollaboration,innovationandeffectivestrategiesforrespondingtoincidentsworldwide.Supportforstandardizeddataprotectionlaws,suchasGDPR,highlightsthecommitmenttosafeguardingsensitiveinformationandensuringitsintegrityandcon?dentiality.Achievingglobalinteroperabilityofcybersecurityregulationsintheelectricitysectordemandsasigni?cantshiftinapproach.Thistransformationinvolvesprioritizingsecuritymeasuresovermereregulatorycompliance,takingaproactivestancetobolstercybersecuritystandardsandensuringahigherlevelofprotection.Itrequirestheestablishmentofconsistentriskevaluations,uniformstandardsandsharedresponsibilitythroughoutthesupplychaintostrengthenthecybersecuritystructureofthesector.Ultimately,thejourneytowardsamoresecureandrobustelectricitysectorinvolvesaligningregulations,fosteringcollaborationandstreamliningendeavoursacrossdiversejurisdictions.Thiscollectiveendeavournotonlymitigatescyberthreatsbutalsopromotesinnovationandcoordinatedresponsemechanisms,thusestablishingaresilientanduni?edglobalcybersecurityapproachwithintheelectricityindustry.FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector8ContributorsLeadauthorKesangTashi
UkyabLead,CyberResilience,ElectricityWorldEconomicForumWorldEconomicForumFilipeBeatoLead,CentreforCybersecurityWorldEconomicForumSCREGlobalRegulationsWorkingGroupleadsChristopheBlassiauSeniorVice-President,CybersecurityandProductSecurity;GlobalChiefInformationSecurityOf?cerandChiefProductSecurityOf?cer,
Schneider-Electric,FranceYuri
G.RassegaChiefInformationSecurityOf?cer(CISO),Head,CyberSecurity,Enel,ItalySCREcommunityJoseManuelAlonsoBarrilJoeDoetzlCISO,Iberdrola,SpainCISO,HitachiEnergy,SwitzerlandStefanoBraccoMortenDuusKnowledgeManager,
ACER,SloveniaChiefInformationSecurityOf?cer,
Vestas,DenmarkMannyCancelSVPandCEOofE-ISAC,NERC,USAMikhailFalkovichChiefInformationSecurityOf?cer,ConsolidatedEdison,USATimConwayDirectorofSCADAandICS,SANSInstitute,USAPeterFr?kj?rSebastijanCuturaSeniorSecurityArchitect,Vestas,DenmarkPolicyManager,
EuropeanCyberSecurityOrganisation,BelgiumLorisGasparriniHeadofCyberSecurityStandardsandExternalStakeholders,Enel,ItalyTodd
DavisHeadofCyberRisk&StrategyTrends,
Vestas,DenmarkAgustínValenciaGil-OrtegaOTSecurityBusinessDevelopment,Fortinet,SpainMarkAntonyD’AmbrogioRegionalInformationSecurityOf?cer,
Orsted,UnitedKingdomDavidAndresHurtadoHeadofOTCybersecurity&Resilience,Naturgy,SpainGabrieleDeLucaCybersecurityExpert,Enel,ItalyFrederikLille?reJ?gerChiefInformationSecurityOf?cer,
Orsted,DenmarkFacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector9RosaKarigerGabriellaSerinoGlobalSecurityGovernance&Intelligence,Iberdrola,SpainCyberExpert,Enel,ItalyLeoSimonovichJesusSanchezLopezHeadofGlobalCybersecurity,Naturgy,SpainVicePresident;GlobalHead,IndustrialCyberandDigitalSecurity,SiemensEnergy,USAStuartMadnickHenrikLothThiesenJohnNorrisMaguireProfessorofInformationTechnologiesandProfessorofEngineeringSystems,MIT–SloanSchoolofManagement,USAGlobalDirectorofInformationSecurity&RiskManagement,Vestas,DenmarkPhilipTonkinAngelicaMarottaChiefofStaff,Dragos,UnitedKingdomAf?liatedResearcher,
Cybersecurity,MassachusettsInstituteofTechnology,
USAMaximilianUrbanInformationSecurityOf?cerandInnovationManager,
NetzNieder?sterreich,AustriaPauloMonizDirector-InformationSecurityandITRisk,EDP-EnergiasdePortugal,PortugalSwantjeWestpfahlCEO,InstituteforSecurityandSafety(ISS),GermanyCharmaine
溫馨提示
- 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶(hù)所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶(hù)上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶(hù)上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶(hù)因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 企業(yè)內(nèi)部培訓(xùn)師招聘合同書(shū)
- 水泥行業(yè)托盤(pán)租賃協(xié)議
- 2024年軟件開(kāi)發(fā)合作合同3篇
- 影視基地建設(shè)管理策略
- 汽車(chē)維修質(zhì)量異常處理要點(diǎn)
- 臨時(shí)演員加入企業(yè)年會(huì)合同
- 網(wǎng)絡(luò)教育副總經(jīng)理招聘合同
- 停車(chē)場(chǎng)導(dǎo)向牌安裝協(xié)議
- 城市綠化施工總承包合同
- 泥水匠勞動(dòng)合同模板
- 國(guó)家開(kāi)放大學(xué)電大專(zhuān)科《刑法學(xué)(1)》題庫(kù)及答案
- 項(xiàng)目部管理人員通訊錄
- 人教版高一數(shù)學(xué)必修一各章節(jié)同步練習(xí)(含答案)
- 班組長(zhǎng)績(jī)效管理課件
- 行業(yè)代碼大全
- 改進(jìn)維持性血液透析患者貧血狀況PDCA
- 術(shù)前術(shù)后健康宣教
- 煙葉制絲操作工(中級(jí))技能檢定考試題庫(kù)(附答案)
- 新東方國(guó)際游學(xué)報(bào)名表
- 數(shù)學(xué)八年級(jí)下冊(cè)第十七章 小結(jié)與復(fù)習(xí)
- 《哈佛管理制度全集-中文》
評(píng)論
0/150
提交評(píng)論