G2TT
来源类型Report
规范类型报告
DOIhttps://doi.org/10.7249/RRA1265-4
来源IDRR-A1265-4
Managing Response to Significant Cyber Incidents: Comparing Event Life Cycles and Incident Response Across Cyber and Non-Cyber Events
Quentin E. Hodgson; Aaron Clark-Ginsberg; Zachary Haldeman; Andrew Lauland; Ian Mitch
发表日期2022-05-12
出版年2022
语种英语
结论

Various factors may make responding to a significant cyber incident more challenging

  • The preparations for significant cyber incidents in comparison with terror attacks, natural hazards, and public health emergencies are more complex due to the low likelihood of advanced warning, the high degree of uncertainty around an incident's scope and scale, the relative inexperience with responding to significant cyber incidents, and the high degree of diversity across responder groups.
  • High uncertainty in the early stages of a cyber incident can make initial interventions difficult to calibrate correctly because the vectors that lead to a standard cyber incident and a significant cyber incident are often similar.
  • The timing of an incident and the potential for multiple attacks can also pose challenges for responders, who may find it more difficult to coordinate as the cyber incident unfolds.

The disparities in response capabilities among entities — both public and private — are also a consideration for cyber incidents

  • Domestic cyber incident response still largely depends on voluntary coordination and cooperation between U.S. public and private sectors.
  • The U.S. response to natural hazards is built on decades of operational experience, while terrorist and significant cyber incidents are less frequent.
  • Despite efforts to establish processes for cyber incident response, the lack of experience in exercising those mechanisms in a robust manner means that it remains unclear how successful those efforts will be once implemented.
  • Some affected entities may not wish to share information on an incident, whether because of concerns over legal liabilities, reputational impact, or other factors.
摘要

Cyber incident response has evolved based on systems and processes developed for other types of incident response, such as response to natural hazards. Large-scale cyber incidents that would have an impact on the United States' national and homeland security, economic security, and public safety and welfare to date are rare. However, they may have additional complications that make them more complex to plan for, including challenges in distinguishing the early stages of a significant cyber incident from a more quotidian incident, and the diversity of stakeholders involved. In this report, RAND researchers compare and contrast incident response for cyber and other types of hazards, both human-caused and natural, to derive initial insights into their similarities and distinctions. The report suggests some ways to improve preparedness for cyber incident response and propose additional areas requiring further research. Recommendations include developing more rigorous and dynamic joint public-private exercises, conducting further analysis to identify how systems could fail through a cyber attack to inform early warning efforts, and developing decision mechanisms and shared understandings that will facilitate coordinated activation and execution of incident response plans.

目录
  • Chapter One

    Introduction

  • Chapter Two

    Key Features of Non-Cyber Incidents

  • Chapter Three

    Life Cycle of Significant Cyber Incidents

  • Chapter Four

    Cross-Incident Analysis

  • Chapter Five

    Recommendations and Areas for Future Research

主题Cyber Warfare ; Cybercrime ; Emergency Preparedness ; Natural Hazards ; United States
URLhttps://www.rand.org/pubs/research_reports/RRA1265-4.html
来源智库RAND Corporation (United States)
引用统计
资源类型智库出版物
条目标识符http://119.78.100.153/handle/2XGU8XDN/524795
推荐引用方式
GB/T 7714
Quentin E. Hodgson,Aaron Clark-Ginsberg,Zachary Haldeman,et al. Managing Response to Significant Cyber Incidents: Comparing Event Life Cycles and Incident Response Across Cyber and Non-Cyber Events. 2022.
条目包含的文件
文件名称/大小 资源类型 版本类型 开放类型 使用许可
RAND_RRA1265-4.pdf(966KB)智库出版物 限制开放CC BY-NC-SA浏览
x1651518150068.jpg.p(4KB)智库出版物 限制开放CC BY-NC-SA浏览
个性服务
推荐该条目
保存到收藏夹
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Quentin E. Hodgson]的文章
[Aaron Clark-Ginsberg]的文章
[Zachary Haldeman]的文章
百度学术
百度学术中相似的文章
[Quentin E. Hodgson]的文章
[Aaron Clark-Ginsberg]的文章
[Zachary Haldeman]的文章
必应学术
必应学术中相似的文章
[Quentin E. Hodgson]的文章
[Aaron Clark-Ginsberg]的文章
[Zachary Haldeman]的文章
相关权益政策
暂无数据
收藏/分享
文件名: RAND_RRA1265-4.pdf
格式: Adobe PDF
文件名: x1651518150068.jpg.pagespeed.ic.kXHso4Rzt0.jpg
格式: JPEG

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。