User Tools

Site Tools


cbdc:public:cbdc_omg:04_doc:20_comments:brp:q11:start

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
cbdc:public:cbdc_omg:04_doc:20_comments:brp:q11:start [2022/04/24 15:35]
nick [6. Risk of Meta-Data being hacked due weak Security Infrasture]
cbdc:public:cbdc_omg:04_doc:20_comments:brp:q11:start [2022/06/17 18:59] (current)
terrance
Line 1: Line 1:
-====== Question: 11. TBD Are there additional ways to manage potential risks associated with CBDC that were not raised in this paper? ====== +====== Question: 11. Are there additional ways to manage potential risks associated with CBDC that were not raised in this paper? ====== 
-[[cbdc:private:​cbdc_omg:​04_doc:​20_comments:​brp:​start| Return to CBDC Benefits, Risks, and Policy Considerations ]]+|< 100% >| 
 +[[cbdc:public:​cbdc_omg:​04_doc:​20_comments:​brp:​start| Return to CBDC Benefits, Risks, and Policy Considerations ]]  ​| ​ <​WRAP>​ 
 +<​html><​b>​ 
 +<a href="​mailto:​[email protected]?​Subject=OMG'​s CBDC WG Response:  
 +Question: 11. Are there additional ways to manage potential risks associated with CBDC that were not raised in this paper? 
 +">​Provide Feedback</​a></​b>​ 
 +</​html>​ 
 +</​WRAP> ​ |
  
 ===== Question ===== ===== Question =====
-[[cbdc:private:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]]+[[cbdc:public:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]]
  
 **Are there additional ways to manage potential risks associated with CBDC that were not raised in this paper?** **Are there additional ways to manage potential risks associated with CBDC that were not raised in this paper?**
  
 ===== Answer ===== ===== Answer =====
-[[cbdc:private:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]]+[[cbdc:public:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]]
  
 By all descriptions,​ the U.S. CBDC is primarily a large [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​s:​sos | System-of-Systems (SoS)]] or even an SoS of SoSs. Some of these would ideally already exist and some will need to be created. The new systems are predominately a [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​s:​software | Software (SW)]] effort. Yes, there will be some specialized [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​h:​hardware | Hardware(HW) ]] required, but the primary focus appears to be Software (including [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​c:​cots | Commercial-Off-The-Shelf (COTS)]], [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​g:​gots | Government Off-The-Shelf (GOTS)]], or [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​m:​mots | Modified Off-The-Shelf (MOTS)]]. This software will ultimately need to be  [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​1.4_req:​2_nonfunc:​28_manageability:​04_costs | Managed ]] and [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​1.4_req:​2_nonfunc:​20_maintainability:​modifiability | Modified]]. By all descriptions,​ the U.S. CBDC is primarily a large [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​s:​sos | System-of-Systems (SoS)]] or even an SoS of SoSs. Some of these would ideally already exist and some will need to be created. The new systems are predominately a [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​s:​software | Software (SW)]] effort. Yes, there will be some specialized [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​h:​hardware | Hardware(HW) ]] required, but the primary focus appears to be Software (including [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​c:​cots | Commercial-Off-The-Shelf (COTS)]], [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​g:​gots | Government Off-The-Shelf (GOTS)]], or [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​m:​mots | Modified Off-The-Shelf (MOTS)]]. This software will ultimately need to be  [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​1.4_req:​2_nonfunc:​28_manageability:​04_costs | Managed ]] and [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​1.4_req:​2_nonfunc:​20_maintainability:​modifiability | Modified]].
 +
 +The following is a list of potential risks not identified in the **White Paper**.
  
 <nspages -tree -r -exclude -subns -pagesInNs -h1 -textNs="">​ <nspages -tree -r -exclude -subns -pagesInNs -h1 -textNs="">​
  
-==== 1. Risk of a Software Crisis ==== 
-[[cbdc:​private:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]] 
- 
- 
-==== 2. Risk of Lack of Stakeholder Buy-In ===== 
-[[cbdc:​private:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]] 
- 
- 
- 
-==== 3. Risk due to Poor Community of Interest (CoI) Governance ==== 
-[[cbdc:​private:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]] 
- 
- 
-==== 4. Risk due to lack of Broad, Wide Ranging Security Planning ==== 
-[[cbdc:​private:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]] 
- 
- 
-==== 5. Risk of Data being hacked due weak Security Infrasture ==== 
-[[cbdc:​private:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]] 
- 
- 
-==== 6. Risk of Meta-Data being hacked due weak Security Infrasture ==== 
-[[cbdc:​private:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]] 
- 
- 
-==== 7. Risk of Business Processes Being Hacked ==== 
-[[cbdc:​private:​cbdc_omg:​04_doc:​20_comments:​brp:​q11:​start| Return to Top]] 
- 
-Some government business processes need to be kept confidential,​ secret, or even top-secret when it comes to trying to audit or discover illegal or criminal activities. The reason is that if the processes were made readily available to the public, then the business process can be "​gamed"​ to avoid detection. In these situations, the government is involved in an "arms race" so to speak with those who want to avoid detection. The government business processes are continuously refined and honed to detect illegal or criminal activity, while the "bad guys" continuously test the system to find its weaknesses. ​ 
- 
-As an example, the process of trying to "​reverse engineer"​ the "​rules"​ of a government business process for determining if an individual return gets audited run rampant when it comes to triggering an audit by the Internal Revenue Service (IRS).(( 
-Jacob Dayan, 
-__IRS Audits: 10 Common Myths Debunked__, 
-Accessed: 24 April 2022, 
-[[https://​articles.bplans.com/​irs-audits-10-common-myths-debunked/​]] 
-)) 
- 
-More and more government business processes are using Artificial Intelligence (AI) to aid in the flow of the business process. Many of these AI processes are data-driven either through parameters or by using learning datasets continuously refined based on previous runs through the process. This means that either the original parameters or the learning data sets are subject to hacking attempts. 
- 
-  : //Budget cuts and a significant drop in Special Agents that investigate criminal tax crimes have led the IRS to use Artificial Intelligence (AI) to uncover criminal tax activities. In a recent webcast hosted by the American Bar Association,​ the IRS revealed that research and investigative techniques that used to take weeks or months may now be accomplished in minutes with technology the IRS is rolling out to detect taxpayer noncompliance.//​ 
- 
-  : //These computer tools are able to detect fraud, identity theft, money laundering, and hidden assets that Revenue Agents and Special Agents typically look for manually. The speed and sophistication of these computer data-mining programs have greatly increased the IRS’ efficiency.//​(( 
-Stahl Criminal Defense Lawyers, 
-Accessed: 24 April 2022, 
-[[https://​stahlesq.com/​irs-artificial-intelligence-detects-tax-evaders/​]] 
-)) 
- 
-If the government business processes are hacked, then the ability for illegal or criminal activities to go undetected is advanced. 
- 
-Another problem would be if the government'​s business processes themselves were "​hacked"​ to disable the government process or change the algorithms or parameters of the process to provide an unfair advantage. A simple example might be adding an exclusion for a certain individual within the process. 
  
 /​**=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- /​**=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
cbdc/public/cbdc_omg/04_doc/20_comments/brp/q11/start.1650828937.txt.gz · Last modified: 2022/04/24 15:35 by nick