This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
cbdc:public:cbdc_omg:04_doc:20_comments:brp:q13:sb_01:prt_b:start [2022/05/18 00:15] nick |
cbdc:public:cbdc_omg:04_doc:20_comments:brp:q13:sb_01:prt_b:start [2022/06/17 19:12] (current) terrance |
||
|---|---|---|---|
| Line 3: | Line 3: | ||
| | [[cbdc:public:cbdc_omg:04_doc:20_comments:brp:q13:sb_01:start| Return to Question 13-1 ]] | <WRAP> | | [[cbdc:public:cbdc_omg:04_doc:20_comments:brp:q13:sb_01:start| Return to Question 13-1 ]] | <WRAP> | ||
| <html><b> | <html><b> | ||
| - | <a href="mailto:[email protected]?Subject=OMG CBDC Response: | + | <a href="mailto:[email protected]?Subject=OMG's CBDC WG Response: |
| 13.1.b) Cyber Resiliency | 13.1.b) Cyber Resiliency | ||
| ">Provide Feedback</a></b> | ">Provide Feedback</a></b> | ||
| Line 15: | Line 15: | ||
| <figure layerSecure> | <figure layerSecure> | ||
| - | {{ :cbdc:private:cbdc_omg:04_doc:20_comments:brp:q13:sb_01:layers_of_security.png?275 |}} | + | {{ cbdc:04_doc:20_comments:brp:q13:sb_01:layers_of_security.png?275 |}} |
| <caption>The layers of security.</caption> | <caption>The layers of security.</caption> | ||
| </figure> | </figure> | ||
| Line 57: | Line 57: | ||
| Accessed 14 August 2020, | Accessed 14 August 2020, | ||
| [[https://csrc.nist.gov/glossary/term/authenticity | Authenticity]] | [[https://csrc.nist.gov/glossary/term/authenticity | Authenticity]] | ||
| - | )). The process of authenticating a source starts when an [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:e:entity|entity]] (i.e., user, remote process, intelligent agent, etc.) attempts to access resources on a [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:c:computerplaform | Computer Platform]]. The entity proves their identity in order to gain access rights. For example, traditionally when logging into a computer, users use [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:s:sfa | Single-Factor Authentication (SFA) ]], providing a ''username'' and ''password'' to confirm their identity and allow [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:a:authentication|authentication]] for future access to resources. However, the ''username'' and ''password'' login combination is no longer considered secure enough, especially if the [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:c:securityculture | Security Culture]] is poor. As a consequence, many systems have added [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:t:2fa | Two-Factor Authentication (2FA) ]] that require [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:b:biometrics | Biometrics]] (i.e., facial recognition, fingerprints, etc.) or [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:o:otp | One-Time PIN (OTP) ]]. These 2FA methods generally require the user to be physically present to successfully log in. | + | )). The process of authenticating a source starts when an [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:e:entity|entity]] (i.e., user, remote process, intelligent agent, etc.) attempts to access resources on a [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:c:computerplaform | Computer Platform]]. The entity proves its identity in order to gain access rights. For example, traditionally when logging into a computer, users use [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:s:sfa | Single-Factor Authentication (SFA) ]], providing a ''username'' and ''password'' to confirm their identity and allow [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:a:authentication|authentication]] for future access to resources. However, the ''username'' and ''password'' login combination is no longer considered secure enough, especially if the [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:c:securityculture | Security Culture]] is poor. As a consequence, many systems have added [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:t:2fa | Two-Factor Authentication (2FA) ]] that require [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:b:biometrics | Biometrics]] (i.e., facial recognition, fingerprints, etc.) or [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:o:otp | One-Time PIN (OTP) ]]. These 2FA methods generally require the user to be physically present to successfully log in. |
| </WRAP>| | </WRAP>| | ||
| ^ [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:1.4_req:2_nonfunc:25_security:accountability | Accountability ]] | <WRAP> | ^ [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:1.4_req:2_nonfunc:25_security:accountability | Accountability ]] | <WRAP> | ||
| Line 79: | Line 79: | ||
| [[cbdc:public:cbdc_omg:04_doc:20_comments:brp:q13:sb_01:prt_b:start| Return to Top]] | [[cbdc:public:cbdc_omg:04_doc:20_comments:brp:q13:sb_01:prt_b:start| Return to Top]] | ||
| - | An important first step is to follow the NIST Special Publication SP 800-16 volume 2 guidelines for developing cyber-resilient systems.(( | + | An important first step is to follow the NIST Special Publication SP 800-16 volume 2 guidelines for developing cyber-resilient systems. (( |
| Ron Ross, Victoria Pillitteri, Richard Graubart, Deborah Bodeau, Rosalie McQuaid, | Ron Ross, Victoria Pillitteri, Richard Graubart, Deborah Bodeau, Rosalie McQuaid, | ||
| __Developing Cyber-Resilient Systems: A Systems Security Engineering Approach__, | __Developing Cyber-Resilient Systems: A Systems Security Engineering Approach__, | ||