Buch, Englisch, 288 Seiten
Buch, Englisch, 288 Seiten
ISBN: 978-1-394-40740-8
Verlag: John Wiley & Sons Inc
Sound guidance on design, implementation, and governance of cybersecurity policy
Now in its Second Edition, the Cybersecurity Policy Guidebook delivers an issue-focused treatment of public, private, and individual cybersecurity policy alternatives for treatment of systemic cyber risks. Seven practitioners from government, industry, and academia analyze overlapping perspectives of decision-makers, technology professionals, and critical infrastructure engineers within the recently transformed digital landscape.
The first edition dealt with threats to impersonation, infrastructure access, intellectual property, internet access, nation-state conflict, operational continuity, privacy, and supply chain. New to this edition is coverage of AI's impact on cybersecurity, cyber-physical systems, and custodial issues for technology platforms and other cyber-enabled services. The book addresses threat intelligence across industry sectors, governance frameworks, and risk appetite thresholds. A policy catalog reflects pros and cons of pressing policy positions.
Key topics also include: - Communication strategies for conveying cybersecurity risk to decision makers across public and private levels of authority
- Policy objectives mapped to technology evolution, connecting operational choices with their broader strategic and regulatory implications
- Guidance on banking and financial services cybersecurity supervision, drawing on interagency regulatory frameworks and examination standards
- Operational technology and control system cybersecurity policy, addressing risks unique to industrial control systems and other cyber-physical systems
- Cross-disciplinary course alignment for programs in public policy, law, business, computer science, engineering, and social sciences
Cybersecurity Policy Guidebook serves leaders of public and private organizations, as well as technology professionals, industry analysts, scholars, and individuals seeking a structured reference on cybersecurity policy issues. Whatever the starting point of perspective, readers will gain the policy knowledge required to act with precision.
Fachgebiete
Weitere Infos & Material
Chapter 1. Building Blocks
1.1 Definitions
1.2 Cybersecurity Policy Domains
1.2.1 Individuals
1.2.2 Organizations
1.2.3 Dependencies
1.2.4 Adversaries
1.2.5 Cyberspace
1.2.6 Public Policy
1.3 Cybersecurity Policy Catalog
Chapter 2 Cybersecurity Evolution
2.1 The Dawn of the internet
2.2 Timeline
1960s
1970s
1980s
1990s
2000s
2010s
2020s
2.3 Ongoing Challenges
Chapter 3 Cybersecurity Policy Objectives
3.1 Cybersecurity Risk Issues
3.2 Governance and Management
3.2.1 Cybersecurity Policy
3.2.2 Procedures
3.2.3 Guidelines
3.3 Metrics
3.4 Risk Management
3.4.1 Financial Services
3.4.1.1 Contagion Mechanisms
3.4.1.2 Illustrative Contagion Scenarios
3.4.1.3 Contagion Accelerators
3.4.1.4 Case Study: The SWIFT Banking Network
3.4.1.5 From Institutional Risk to Systemic Risk
3.4.1.6 Additional Cybersecurity Challenges in Financial Services
3.4.2 Industrial Control Systems (ICS)
3.4.2.1 Control System Functions
3.4.1.4 Case Study: Stuxnet
3.4.2.2 Operational Technology
3.4.2.3 Level 0
3.4.2.4 Ongoing Challenges
3.4.3. Technology Platforms
3.4.3.1 Dispossession
3.4.3.2 Case Study: Cambridge Analytica
3.4.3.3 Technology Platform Industry Standards
3.4.3.5 Ongoing Technology Platform Cybersecurity Challenges
3.4.4 Artificial Intelligence (AI)
3.4.4.1 Cybersecurity Risk Issues Unique to AI
3.4.4.2 AI Case Study
3.4.4.3 AI Cybersecurity Standards
3.4.4.4 AI Anthropomorphism
3.4.4.3 Ongoing Artificial Intelligence Challenges
3.5 Conclusion
Chapter 4 Cybersecurity Communication
4.1 Cybersecurity Frameworks
4.1.1 Governance and Oversight Frameworks
4.1.2 Cybersecurity Program Frameworks
4.1.3 Dependency Frameworks
4.1.4 Assessing Framework Compliance
4.2 Threats and Vulnerabilities
4.2.1 Threats
4.2.1 Cybersecurity Incidents
4.2.2 Vulnerabilities
4.2.3 Vulnerability Marketplaces
4.3 Institutions for Communication and Collaboration
4.3.1 FIRST
4.3.2 The National Incident Management System and Cybersecurity Incident Coordination
4.3.3 National Infrastructure Protection Plan
4.4 Trend Analysis
4.5 Communication Challenges
4.5.1 Organizational Challenges
4.5.2 IT, OT, and ICS
4.5.3 Vulnerability Reporting
4.5.4 Public/Private Conflicts
4.5.5 Crisis Communications Systems
4.6 Conclusion
Chapter 5 Guidance for Decision Makers
5.1 Innovation, Change, and Risk
5.2 Governance
5.4 Strategic Choices
5.5 Focus on Risk and Controls
5.6 Policy Essentials
5.7 Moving from Policy to Implementation
5.7.1 Implementation of the Controls Architecture
5.8 Conclusion
Chapter 6 The Cybersecurity Workforce
6.1 Cybersecurity versus Engineering
6.2 Academic Curriculum on Cybersecurity
6.3 Certification of Cybersecurity Professionals
6.4 Cybersecurity Job Roles
6.5 Conclusion
Chapter 7: One Government’s Approach to Cyber Security Policy
7.1 US Federal Cyber Security Strategy
7.2 Infrastructure Awareness and Early Coordination
7.2.1 The Bombing of New York's World Trade Center
7.2.2 Cyber Attacks Against the United States Air
7.2.3 The Citibank Caper
7.2.4 Murrah Federal Building, Oklahoma City
7.2.5 Presidential Decision Directive 39
7.2.6 President’s Commission on Critical Infrastructure Protection
7.2.7 Eligible Receiver
7.2.8 Solar Sunrise
7.2.9 Presidential Decision Directive 63
7.2.10 National Infrastructure Protection Center (NIPC) and Information Sharing and Analysis Centers (ISACs)
7.2.12 Joint Task Force – Computer Network Defense (JTF-CND)
7.3 Homeland Security and Federal Consolidation
7.3.1 Terrorist Attacks Against the USA
7.3.2 US Government Response to the September 11, 2001 Terrorist Attacks
7.3.3 Homeland Security Presidential Directives in the Bush Administration
7.3.4 National Strategies in the Bush Administration
7.3.5 First National-Level DDoS Campaign, Estonia
7.3.6 Cyber-Kinetic Coordination, Georgia
7.3.7 Buckshot Yankee (Agent.btz)
7.4 Operationalization of Cyber Power
7.4.1 Early Cyber Warfare, Stuxnet
7.4.2 State Sponsored Espionage
7.4.3 US Cyber Command
7.4.4 Expansion of USCYBERCOM Service Cyber Components
7.4.5 Notable events
7.4.6 Congressional Actions
7.4.7 Federal Cybersecurity and Infrastructure Executive Orders
7.5 Institutional Maturation and Strategic Competition
7.5.1 Integration of Cyber with Joint Operations Doctrine
7.5.2 The Rise of Ransomware as a National Security Threat
7.5.3 Creation of CISA (the DHS Agency)
7.5.4 Election Security and Critical Infrastructure Protection
7.5.5 Solarium Commission
7.6 Systemic Risk, Resilience, and Whole-of-Nation Governance
7.6.1 Supply Chain and Software Assurance Policy
7.6.2 Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
7.6.3 Federal Cybersecurity and Infrastructure Executive Orders
7.6.4 National Cybersecurity Strategy (Biden Administration)
7.6.5 Public-Private Collaboration and Operational Integration
7.6.6 Offensive Cyber Operations and Deterrence Doctrine
7.7 Emerging Policy Frontiers
7.7.1 Zero Trust, Cloud, and Identity Modernization
7.7.2 Quantum Computing and Cryptographic Forecasts
7.7.3 Operational Technology (OT) and Industrial Control Systems (ICS)
7.7.4 Artificial Intelligence Policy and Cognitive Security
7.8 Conclusion
Chapter 8 Cybersecurity Policy Catalog
8.1 Individual Example Policy Statements
8.2 Organization Example Policy Statements
8.3 Public Example Policy Statements
8.4 Adversary Example Policy Statements
8.5 Dependency Example Policy Statements
8.6 Cyberspace Example Policy Statements
Chapter 9 Conclusion




