User Tools

Site Tools


cbdc:public:cbdc_omg:04_doc:20_comments:brp:q13:sb_01:prt_b:start

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
cbdc:public:cbdc_omg:04_doc:20_comments:brp:q13:sb_01:prt_b:start [2022/05/18 00:15]
nick
cbdc:public:cbdc_omg:04_doc:20_comments:brp:q13:sb_01:prt_b:start [2022/06/17 19:12] (current)
terrance
Line 3: Line 3:
 | [[cbdc:​public:​cbdc_omg:​04_doc:​20_comments:​brp:​q13:​sb_01:​start| Return to Question 13-1 ]]  |  <​WRAP>​ | [[cbdc:​public:​cbdc_omg:​04_doc:​20_comments:​brp:​q13:​sb_01:​start| Return to Question 13-1 ]]  |  <​WRAP>​
 <​html><​b>​ <​html><​b>​
-<a href="​mailto:​[email protected]?​Subject=OMG CBDC Response: ​+<a href="​mailto:​[email protected]?​Subject=OMG'​s ​CBDC WG Response: ​
 13.1.b) Cyber Resiliency 13.1.b) Cyber Resiliency
 ">​Provide Feedback</​a></​b>​ ">​Provide Feedback</​a></​b>​
Line 15: Line 15:
  
 <figure layerSecure>​ <figure layerSecure>​
-{{  ​:cbdc:​private:​cbdc_omg:​04_doc:​20_comments:​brp:​q13:​sb_01:​layers_of_security.png?​275 ​ |}}+{{  cbdc:​04_doc:​20_comments:​brp:​q13:​sb_01:​layers_of_security.png?​275 ​ |}}
 <​caption>​The layers of security.</​caption>​ <​caption>​The layers of security.</​caption>​
 </​figure>​ </​figure>​
Line 57: Line 57:
 Accessed 14 August 2020, Accessed 14 August 2020,
 [[https://​csrc.nist.gov/​glossary/​term/​authenticity | Authenticity]] [[https://​csrc.nist.gov/​glossary/​term/​authenticity | Authenticity]]
-)). The process of authenticating a source starts when an [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​e:​entity|entity]] (i.e., user, remote process, intelligent agent, etc.) attempts to access resources on a [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​c:​computerplaform | Computer Platform]]. The entity proves ​their identity in order to gain access rights. For example, traditionally when logging into a computer, users use [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​s:​sfa | Single-Factor Authentication (SFA) ]], providing a ''​username''​ and ''​password''​ to confirm their identity and allow [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​a:​authentication|authentication]] for future access to resources. However, the ''​username''​ and ''​password''​ login combination is no longer considered secure enough, especially if the [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​c:​securityculture | Security Culture]] is poor. As a consequence,​ many systems have added [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​t:​2fa | Two-Factor Authentication (2FA) ]] that require [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​b:​biometrics | Biometrics]] (i.e., facial recognition,​ fingerprints,​ etc.) or [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​o:​otp | One-Time PIN (OTP) ]]. These 2FA methods generally require the user to be physically present to successfully log in.+)). The process of authenticating a source starts when an [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​e:​entity|entity]] (i.e., user, remote process, intelligent agent, etc.) attempts to access resources on a [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​c:​computerplaform | Computer Platform]]. The entity proves ​its identity in order to gain access rights. For example, traditionally when logging into a computer, users use [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​s:​sfa | Single-Factor Authentication (SFA) ]], providing a ''​username''​ and ''​password''​ to confirm their identity and allow [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​a:​authentication|authentication]] for future access to resources. However, the ''​username''​ and ''​password''​ login combination is no longer considered secure enough, especially if the [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​c:​securityculture | Security Culture]] is poor. As a consequence,​ many systems have added [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​t:​2fa | Two-Factor Authentication (2FA) ]] that require [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​b:​biometrics | Biometrics]] (i.e., facial recognition,​ fingerprints,​ etc.) or [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​xapend:​xapend.a_glossary:​o:​otp | One-Time PIN (OTP) ]]. These 2FA methods generally require the user to be physically present to successfully log in.
 </​WRAP>​| </​WRAP>​|
 ^ [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​1.4_req:​2_nonfunc:​25_security:​accountability ​   | Accountability ]] | <​WRAP>​ ^ [[https://​www.omgwiki.org/​dido/​doku.php?​id=dido:​public:​ra:​1.4_req:​2_nonfunc:​25_security:​accountability ​   | Accountability ]] | <​WRAP>​
Line 79: Line 79:
 [[cbdc:​public:​cbdc_omg:​04_doc:​20_comments:​brp:​q13:​sb_01:​prt_b:​start| Return to Top]] [[cbdc:​public:​cbdc_omg:​04_doc:​20_comments:​brp:​q13:​sb_01:​prt_b:​start| Return to Top]]
  
-An important first step is to follow the NIST Special Publication SP 800-16 volume 2 guidelines for developing cyber-resilient systems.((+An important first step is to follow the NIST Special Publication SP 800-16 volume 2 guidelines for developing cyber-resilient systems. ((
 Ron Ross, Victoria Pillitteri, Richard Graubart, Deborah Bodeau, Rosalie McQuaid, Ron Ross, Victoria Pillitteri, Richard Graubart, Deborah Bodeau, Rosalie McQuaid,
 __Developing Cyber-Resilient Systems: A Systems Security Engineering Approach__, __Developing Cyber-Resilient Systems: A Systems Security Engineering Approach__,
cbdc/public/cbdc_omg/04_doc/20_comments/brp/q13/sb_01/prt_b/start.1652847303.txt.gz · Last modified: 2022/05/18 00:15 by nick