MITRE:国家网络馈送实施建议(2024) 4页

VIP文档

ID:71569

大小:2.64 MB

页数:4页

时间:2024-10-18

金币:10

上传者:PASHU
1
CLOUD SAFE TASK FORCE (CSTF)
NATIONAL CYBER FEED (NCF)
IMPLEMENTATION RECOMMENDATIONS
Background
With the rapid expansion of cloud service adoption,
commercial U.S. Cloud Service Providers (CSPs) are
in a unique position to assess and monitor national
cybersecurity risks. The shared responsibility model
in cloud computing has positioned U.S. CSPs as key
contributors to national cyber defense, often placing them
on the front lines of cyber conflict. However, recent high-
profile security breaches impacting both U.S. industries
and government entities have shaken confidence in cloud
services. Addressing these concerns is essential not only
to prevent a potential return to traditional datacenter
models—where operational and security complexities are
heightened—but also to preserve the numerous benefits
cloud services provide. These benefits include scalability,
cost eciency, flexibility, and access to advanced security
tools. A shift away from cloud services would not only
risk losing the innovation, collaboration, and resilience
that cloud environments foster but also reintroduce
complexities, slower threat detection, and ineciencies in
large-scale cybersecurity management.
To tackle these challenges, the Cloud Safe Task Force
(CSTF) was established in September 2023 to develop
comprehensive solutions for U.S. cloud security. The Task
Force is a collaborative initiative led by MITRE, the Cloud
Security Alliance (CSA), the Advanced Technology Academic
Research Center (ATARC), and the IT Acquisition Advisory
Council (IT-AAC). On July 1, 2024, the CSTF convened a
summit to refine its proposal to establish a National Cyber
Feed (NCF) to provide a real-time snapshot of cloud security.
The discussions focused on the government’s need to
monitor data and the challenges CSPs face in delivering
eective cyber risk and threat intelligence.
U.S. CSPs and third-party risk assessment companies
possess world-class capabilities for monitoring risk
and tracking adversary activities. However, the CSTF
concluded that current data feeds provided by CSPs
require improvement to enable real-time threat detection,
response, and defense at a national level. In response to
feedback from CSP members, the CSTF recommends
moving forward with implementation of an NCF. This feed
would aggregate monitoring data from U.S. CSPs, providing
a real-time view of the national security posture, tracking
adversary behavior, and predicting future threats to critical
U.S. infrastructure.
National Cyber Feed Concept
In a recent CSTF meeting, CSP members proposed
an innovative approach: utilizing the advanced cyber
defense dashboards currently deployed by their security
operations teams to strengthen national cyber defense
eorts. The core idea is to aggregate and anonymize data
from these sophisticated dashboards, enabling real-
time risk monitoring across national IT infrastructure.
This data, when made accessible across various sectors
and government agencies, could be used to enhance
collective threat intelligence, drive informed policy
OCTOBER 2024
资源描述:

云安全工作组建议云服务提供商(CSP)与联邦政府共享其实时网络安全仪表板,以改善我们国家的云安全态势。

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭