




版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡介
Facilitating
GlobalInteroperability
ofCyber
Regulations
inthe
Electricity
SectorSYS
T
E
M
S
O
F
CY
B
E
R
R
E
S
I
L
I
E
N
C
E
:E
L
E
C
T
R
I
C
I
T
Y
I
N
I
T
I
A
T
I
V
EP
O
S
I
T
I
O
N
P
A
PE
RN
OV
E
M
B
E
R
20
23Images:GettyImagesContentsIntroduction341
Currentstateofaffairs2
Importanceofglobalregulatoryinteroperability3
10keythemesforglobalregulatoryinteroperability4
CommunitypositiononthekeythemesConclusion5678Contributors9Annex1:Relatedpublications11DisclaimerThisdocumentispublishedbytheWorldEconomicForumasacontributiontoaproject,insightareaorinteraction.The?ndings,interpretationsandconclusionsexpressedhereinarearesultofacollaborativeprocessfacilitatedandendorsedbytheWorldEconomicForumbutwhoseresultsdonotnecessarilyrepresenttheviewsoftheWorldEconomicForum,northeentiretyofitsMembers,Partnersorotherstakeholders.?2023WorldEconomicForum.Allrightsreserved.Nopartofthispublicationmaybereproducedortransmittedinanyformorbyanymeans,includingphotocopyingandrecording,orbyanyinformationstorageandretrievalsystem.FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector2November2023FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySectorIntroductionIntoday’s
interconnectedworld,theelectricitysectorstandsasacornerstoneofsocietalfunctioning,poweringindustries,homesandcriticalinfrastructure.Aspowersystemsgothroughrapiddigitaltransformation,thecriticallinkbetweencybersecurityandtheenergylandscapebecomesincreasinglyevident.Theneedforglobalinteroperabilityincyberregulationsintheelectricitysectorhasbecomeparamount.ThispositionpaperfromtheSystemsofCyberResilience:Electricity(SCRE)initiativeaimstoconsolidateacohesivestancefromtheelectricitysectoroncybersecurity.Itadvocatesforinteroperabilityamongnationstocultivateacybersecure,resilientandstandardizedapproacharoundtheworld.Byscrutinizingthecurrentlandscapeofcyberregulations,thepaperendeavourstotackleexistinggapsandcomplexitieswhileproposingcollectivepositionstostandardizecybersecuritypracticesacrossdiverseregulatoryenvironments.Itsobjectiveistochampioninternationalcooperation,mutualunderstandingandtheadoptionofcommonstandardstofortifytheelectricitysectoragainstemergingcyberthreatswhileencouraginginnovationandgrowth.Theevolutionoftechnologyhassigni?cantlyreshaped
theelectricityindustry,usheringinsmartergrids,integrationofrenewable
energyandimproved
operationalef?ciencies.
However,thisevolutionpresents
a
newsetofchallenges,particularlyinsafeguarding
theseintricatesystemsfrom
cyberthreats.
Theincreasinginterdependencies
amongpowersystemsacross
borders
andthegrowing
sophisticationofcyberattacksunderscore
theimportanceofaharmonized,globalapproach
tocybersecurityregulations
intheelectricitysector.Ultimately,thispositionpaperstrivestocontributetotheongoingdiscourseonharmonizationofregulationstonurtureasecure,interoperableandresilientglobalelectricityecosystem,ensuringareliableandsafeenergysupplyfortheworld’spopulationinanincreasinglydigitalizedworld.TheSystemsofCyberResilience:ElectricityInitiativeSince2018,theWorldEconomicForum’s
SystemsofCyberResilience:Electricity(SCRE)initiativehasbroughttogetherrepresentativesofover60electricityutilities,energyserviceproviders,regulatorybodiesandotherpertinentorganizationsworldwide.Theireffortsaimtoachievecooperationandfortifyacyberresilientelectricityecosystem.TheSCREstandsoutastheonlyglobalpublic-privatepartnershiptailoredfortheelectricityindustry,wherecybersecurityexpertscollaboratetoenhanceresilienceacrosstheelectricityecosystem.Itis
a
great
opportunityto
createa
collaborativeenvironment,focused
onincreasing
globalcyberresilience,
basedonthe
sharingof
information,on
thedevelopment
of
commoninitiatives,
onthede?nitionof
principles
andthe
alignmentaround
them
bythe
mainactorsof
our
industry.Jesús
Sánchez,
Headof
Global
Cybersecurity,NaturgyTheGlobalRegulationsWorkingGroupInSeptember2022,theSCREcommunityhadidenti?edglobalregulatoryinteroperabilityintheelectricitysectorasoneofitskeyfocusareas,andhadsetuptheGlobalRegulationsworkinggrouptowardsthisend.electricitysector,
markedbyfragmentation,inconsistencyandsporadiccon?icts.Theseregulatorybarriersimpedetheattainmentofglobalinteroperability,resultinginincreasedcosts,inef?cienciesandmissedopportunities.Resourcesaredivertedtoresolveregulatoryissuesratherthanimprovingcybersecurityposturesspeci?ctothesectoranditsvariousorganizations.TheworkinggroupaddressestheintricateglobalregulatorychallengesprevalentthroughouttheFacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector3Current
stateofaffairs1Regulatorsandgovernmentagenciesresponsibleforestablishingcybersecurityrequirements
invariousindustriesworldwideoftenadoptdifferentapproaches
totacklesimilarcybersecuritychallengesduetothelackofa
globalconsensus.Thisresults
incomplex,industry-agnostic,fragmented,inconsistentandoccasionallycon?ictingsetsofregulations.
Theseregulationsnotonlylackmutualinteroperability
butactivelyhinderit.Thedynamicnature
ofcybersecuritythreats
furthercompoundstheproblem
asregulators
frequently
tightenregulations
inresponse.
Thisforces
organizationstoallocatetheirlimitedresources
towards
complianceratherthanconcentratingonbolsteringtheircybersecuritydefences.Moreover,
there
isa
pressing
concerntoensure
thatregulatory
interoperability
doesnotcompromise
nationalsecurity.Nationsmuststrikea
balancebetweentheneedfora
collectivecybersecurityfront
andtheneedtoprotect
theirindividualinterests
andsecurity.Despitetheobstacles,solutionscanbefound.Initiativessuchasworkinggroups,internationalforumsandcollaborativeagreementscanplayapivotalroleinpromotingdialogueandestablishingrobustsystemstomonitor,
evaluateandupdateregulatoryframeworks.Thesemechanismsnotonlycontributetoamoresecureandresilientdigitallandscapebutalsofosterinnovationandgrowth.Manyregulatorsandgovernmentagencieshavebeguntorecognizetheneedforregulatoryharmonizationandmultipleeffortshavebeenputintopractice,suchastheEuropeanCommission’sCyberResilienceAct(CRA)andtheWhiteHouseOf?ceoftheNationalCyberDirector(ONCD)’srequestforinformation(RFI)oncybersecurityregulatoryharmonization.Achievingregulatory
interoperabilitymaypresentchallenges.Differencesincybersecuritystandards,legalsystemsandnationalprioritiesamongvariousjurisdictions
can
lead
to
con?icts
and
inconsistencies,makingitdif?culttoestablishandmaintaininteroperabilityovertime.Onenotablechallengeistheissueofdataprivacylaws,asdifferentcountrieshaveuniquedataprotection
regulations
tailoredtotheircultural,economicandpoliticallandscapes.Simultaneously,severalinternationaldialoguesaregoingonbetweenstates,suchastheEU-USCyberDialogue,US-JapanCyberDialogueandFrance-UnitedKingdomCyberDialogue,inadditiontoregulatoryreciprocityschemessuchastheEU-USDataPrivacyFramework,SingaporeCybersecurityLabellingSchemeandAPECCross-BorderPrivacyRules(CBPR)system.Asimilarchallengearisesinincidentreportinglaws.Forinstance,somecountriesmandatethereportingofalldatabreaches,regardlessoftheirseverity,whileothershavethresholdsforreportingbasedonthenumberofaffectedindividualsorthelevelofharm.Thesedifferencescancreatedif?cultiesinincidentresponseandinformationsharing,particularlyincaseswhereabreachspansmultiplejurisdictions.Creatingsynergyamongthesediverseregulationsisacomplexandintricateprocess,especiallygiventherapidpaceofdigitalinnovation.Thisdynamicenvironmentnecessitatesconstantupdatesandrevisionstoensuretheregulationsremainrelevantandeffective.Whiletheseeffortsareintherightdirection,theyarefarfromachievingglobalinteroperabilityandmuchworkremainstobedonebyboththepublicandprivatesectorstobuildamorecyberresilientelectricityecosystem.FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector4Importanceofglobalregulatoryinteroperability2Aligningcybersecurityregulationsgloballyensuresuniformcybersecuritypractices,enablingcompaniesoperatingacrossmultipleregionstoadheretoconsistentstandards.Harmonizationreducescomplexityandconfusion,simplifyingcomplianceefforts.
Moreover,
interoperabilityfostersenhancedcollaborationandinformationsharingamongvariousentitiesglobally,facilitatingjointeffortstocombatcyberthreatsandexchangebestpractices.bolsteringoverallcyberresilience.Aharmonizedregulatorylandscapefostersafairplaying?eld,encouraginginnovationandthedevelopmentofnewcybersecuritytechnologies,freefromvaryingcompliancerequirements.Inacyberincidentwithglobalimplications,uniformregulationsenableacoordinatedandef?cientresponseacrossmultiplejurisdictions,signi?cantlymitigatingtheimpactofsuchincidents.Giventheglobalspreadofsupplychains,beingabletorelyonsharedprevention,mitigation,informationsharingandincidentresponsepracticeswillleadtoamoresustainable,cyberresilientecosystemworldwide.Ultimately,regulatoryinteroperabilityforcybersecurityaroundtheworldisimperativetofosteramoresecuredigitalandphysicalenvironment.Itcanalignstandards,promotecollaboration,reducecostsandeffectivelymanageandrespondtocyberthreatsworldwide.Auni?edapproachtocybersecurityregulationsallowsforacomprehensiveunderstandingandmanagementofrisks,transcendingdifferentregionsintheelectricityindustry.Standardizingregulationsminimizesthecomplexityandcostsofcomplianceforglobalcorporations,eliminatingtheneedtonavigateamultitudeofdivergentregulations.Globalinteroperabilityalsoleadstomorerobustdefencemechanismsagainstcyberthreatsbyenablingstandardizedcybersecuritypractices,510keythemesforglobalregulatoryinteroperability3Afteranalysingmultipleregulations,thecommunityhasidenti?ed10keyglobalregulatorythemesforregulatorstoconsider.FIGURE1
KeythemesforfacilitatingglobalinteroperabilityofcyberregulationsComplianceandenforcementAdoptionofexistinginternationalstandardsDataprotectionandprivacy10keythemesforfacilitatingglobalinteroperabilityThird-partyriskmanagementInformationsharingofcyberregulationsRiskassessmentandmanagementIncidentresponseandreportingVulnerabilitydisclosureandmanagementInternalpoliciesandproceduresforcybersecurityhygienePenetrationtestingSource:SCREGlobalRegulationsworkinggroup.FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector6Communitypositiononthekeythemes4TheSCREGlobalRegulationsworkinggrouphasadoptedthefollowingpositionsonthe10keyglobalregulatorythemes:6.
Penetrationtesting:Globalcommitmenttoregularinternalpenetrationtesting,whichincludesoperationaltechnology(OT)penetrationtesting.Thisallowsforidentifyingandaddressingpotentialweaknessesinsystemsandinfrastructure,fortifyingdefencesagainstcyberthreats.1.
Complianceandenforcement:
Globalcommitmenttoprioritizecybersecuritybestpracticesovercompliance.Thisimpliesa
shiftinmindset.Insteadofmerely
meetingregulatoryrequirements,
thefocusisonprioritizing7.
Vulnerabilitydisclosureandmanagement:Globalcommitmenttosectorialvulnerabilitydisclosureamongclosedgroupsofsector-speci?c,pre-authorizedentities.Thiswouldfosterasecureenvironmentforinformationsharingwithinclosedgroups,allowingforproactiveresolutionofvulnerabilitieswithoutriskingwidespreadexposure.cybersecuritymeasures
andprotocols,
sometimesbeyondwhatismandated.Thisapproachemphasizesa
proactive
stanceinensuringa
highlevelofcybersecurityratherthanjustcheckingtheboxestocomplywithregulations.2.
Dataprotectionandprivacy:GlobalcommitmenttosupportdataprotectionandprivacyregulationssuchastheGeneralDataProtectionRegulation(GDPR)oftheEuropeanUnion(EU).Thiscommitmentindicatesarecognitionoftheimportanceofsafeguardingsensitiveinformation.Itsambitincludesdataprivacy,ensuringthecon?dentiality,integrityandavailabilityofdatawhilealigningwiththeprinciplesofprivacybydesignanddefault.8.
Riskassessmentandmanagement:Globalcommitmenttoapplyingriskassessmentmethodologyconsistentlyacrossinformationtechnologyandoperationaltechnologyenvironments.ApplyingconsistentriskassessmentmethodologyacrossITandOTenvironmentsensuresacomprehensiveunderstandingofpotentialrisks,allowingforbetter-informedandtimelydecision-makingregardingcybersecuritymatters.3.
Informationsharing:Globalcommitmenttocreateanduseacommoninformation-sharingprotocolandtaxonomyworldwide,andtosupporttherespectiveelectricityinformationsharingandanalysiscentres(ISACs).9.
Third-partyriskmanagement:
Globalcommitmentthateveryorganizationinthesupplychainmustconsiderandberesponsibleforthecybersecurityofitsscopeofwork.Thiswouldensure
a
comprehensive
approachtomanagingandmitigatingrisksassociatedwiththird-party
involvement,securingandembracingecosystem-wideresilience
intheelectricitysector.Establishingacommoninformation-sharingprotocolandtaxonomygloballyisvital.Itallowsforconsistentcommunicationandcollaborationamongvariousstakeholdersintheelectricitysector,
enhancingtheabilitytopromptlyidentifyandrespondtothreats.ThiscommitmentextendstosupportingISACs.10.
Adoptionofexistinginternationalstandardsversuscreationofunique,national(orregional)standards:
GlobalcommitmenttoadoptionofmatureexistinginternationalstandardssuchasISO27001andtheISA/IEC62443series.Adoptingexistinginternationalstandardsratherthancreatinguniqueregionalstandardswouldensurea
moreuniversallyacceptedandharmonizedapproachto4.
Incidentresponseandreporting:
Globalcommitmenttoadopta
commonandef?cientinternational
incidentreportingtaxonomyandrequirements.Thiscommitmentwouldensureastandardized
approachtoreportingcybersecurityincidents.Sucha
taxonomyfacilitatesa
betterandsharedunderstandingofthenatureandimpactofincidents,enablinga
coordinatedandtimelyresponsebothwithinandacross
borders.cybersecuritypractices,leveragingestablishedbestpractices.Thesestandardsshouldbeupdatedwhenneededtoallowfora
harmonizedapproachtoglobalregulationsinsteadoffrequentchangestryingtoaccountforevolvingtechnologiesandthreats.5.
Cybersecurityhygieneinternalpoliciesandprocedures:Globalcommitmenttoestablishbasiccyberhygieneprinciplesspeci?ctotheelectricitysector.
Thiscommitmentwouldprovideforafoundationallevelofsecurityacrossalloperations,reducingvulnerabilities,enhancingoverallresilienceandpromotingacybersecurityculture.FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector7ConclusionThesecollectivecommitmentshelpregulatorsandotherstakeholdersintheelectricitysectortoshareacommonvisionandunderstandwhattheelectricitysectordeemsasimportanttobecyberresilient.Together,
theyembodythedirectionthattheglobalcommunityisheadingtowards.Additionally,theadoptionofinternationalstandardsandthepromotionofsecureinformation-sharingenvironmentsplayacriticalrole.Theseactionsencouragecollaboration,innovationandeffectivestrategiesforrespondingtoincidentsworldwide.Supportforstandardizeddataprotectionlaws,suchasGDPR,highlightsthecommitmenttosafeguardingsensitiveinformationandensuringitsintegrityandcon?dentiality.Achievingglobalinteroperabilityofcybersecurityregulationsintheelectricitysectordemandsasigni?cantshiftinapproach.Thistransformationinvolvesprioritizingsecuritymeasuresovermereregulatorycompliance,takingaproactivestancetobolstercybersecuritystandardsandensuringahigherlevelofprotection.Itrequirestheestablishmentofconsistentriskevaluations,uniformstandardsandsharedresponsibilitythroughoutthesupplychaintostrengthenthecybersecuritystructureofthesector.Ultimately,thejourneytowardsamoresecureandrobustelectricitysectorinvolvesaligningregulations,fosteringcollaborationandstreamliningendeavoursacrossdiversejurisdictions.Thiscollectiveendeavournotonlymitigatescyberthreatsbutalsopromotesinnovationandcoordinatedresponsemechanisms,thusestablishingaresilientanduni?edglobalcybersecurityapproachwithintheelectricityindustry.FacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector8ContributorsLeadauthorKesangTashi
UkyabLead,CyberResilience,ElectricityWorldEconomicForumWorldEconomicForumFilipeBeatoLead,CentreforCybersecurityWorldEconomicForumSCREGlobalRegulationsWorkingGroupleadsChristopheBlassiauSeniorVice-President,CybersecurityandProductSecurity;GlobalChiefInformationSecurityOf?cerandChiefProductSecurityOf?cer,
Schneider-Electric,FranceYuri
G.RassegaChiefInformationSecurityOf?cer(CISO),Head,CyberSecurity,Enel,ItalySCREcommunityJoseManuelAlonsoBarrilJoeDoetzlCISO,Iberdrola,SpainCISO,HitachiEnergy,SwitzerlandStefanoBraccoMortenDuusKnowledgeManager,
ACER,SloveniaChiefInformationSecurityOf?cer,
Vestas,DenmarkMannyCancelSVPandCEOofE-ISAC,NERC,USAMikhailFalkovichChiefInformationSecurityOf?cer,ConsolidatedEdison,USATimConwayDirectorofSCADAandICS,SANSInstitute,USAPeterFr?kj?rSebastijanCuturaSeniorSecurityArchitect,Vestas,DenmarkPolicyManager,
EuropeanCyberSecurityOrganisation,BelgiumLorisGasparriniHeadofCyberSecurityStandardsandExternalStakeholders,Enel,ItalyTodd
DavisHeadofCyberRisk&StrategyTrends,
Vestas,DenmarkAgustínValenciaGil-OrtegaOTSecurityBusinessDevelopment,Fortinet,SpainMarkAntonyD’AmbrogioRegionalInformationSecurityOf?cer,
Orsted,UnitedKingdomDavidAndresHurtadoHeadofOTCybersecurity&Resilience,Naturgy,SpainGabrieleDeLucaCybersecurityExpert,Enel,ItalyFrederikLille?reJ?gerChiefInformationSecurityOf?cer,
Orsted,DenmarkFacilitatingGlobalInteroperabilityofCyberRegulationsintheElectricitySector9RosaKarigerGabriellaSerinoGlobalSecurityGovernance&Intelligence,Iberdrola,SpainCyberExpert,Enel,ItalyLeoSimonovichJesusSanchezLopezHeadofGlobalCybersecurity,Naturgy,SpainVicePresident;GlobalHead,IndustrialCyberandDigitalSecurity,SiemensEnergy,USAStuartMadnickHenrikLothThiesenJohnNorrisMaguireProfessorofInformationTechnologiesandProfessorofEngineeringSystems,MIT–SloanSchoolofManagement,USAGlobalDirectorofInformationSecurity&RiskManagement,Vestas,DenmarkPhilipTonkinAngelicaMarottaChiefofStaff,Dragos,UnitedKingdomAf?liatedResearcher,
Cybersecurity,MassachusettsInstituteofTechnology,
USAMaximilianUrbanInformationSecurityOf?cerandInnovationManager,
NetzNieder?sterreich,AustriaPauloMonizDirector-InformationSecurityandITRisk,EDP-EnergiasdePortugal,PortugalSwantjeWestpfahlCEO,InstituteforSecurityandSafety(ISS),GermanyCharmaine
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 合股開餐廳合同范本
- 衛(wèi)生清潔合同范本
- 勞務(wù)派遣合同范本2003
- 個(gè)人供貨客戶合同范本
- 合股認(rèn)購合同范本
- 合伙協(xié)議書范本合同范本
- 叉車工聘用合同范本
- 員工合同范例送水
- 傳單兼職人員合同范本
- 劇組財(cái)務(wù)合同范本
- 入托入學(xué)兒童預(yù)防接種證查驗(yàn)接種證工作課件
- 《犀牛軟件基礎(chǔ)教程》課件
- 【村級財(cái)務(wù)管理問題探究國內(nèi)外探究綜述3300字】
- 智慧城市新篇章2024年智慧城市發(fā)展機(jī)遇展望
- 工程分包商履約情況與進(jìn)度關(guān)聯(lián)分析
- 培訓(xùn)業(yè)務(wù)的競爭對手分析與對策
- 供應(yīng)商QSA-QPA評鑒表
- 安全生產(chǎn)個(gè)臺賬內(nèi)容
- 建設(shè)工程項(xiàng)目-月度安全檢查表
- 硬件設(shè)計(jì)的模塊化
- 貴州教育大講堂《科技教育之美“中國天眼”的前世今生》觀后感11篇
評論
0/150
提交評論