Requesting WG chairs and experts to review - Block 14 Cybersecurity - Information Sharing 1&2

@Tomofumi_Okubo @JBringer @Mitchell @Shohei_Mitani

Hello Cybersecurity WG,

Please review the draft for the Cybersecurity - Information Sharing sessions 1&2 below, and provide your comments and feedback by March 27.

Thank you

Rola

Security_Cyber_Security_Information_Sharing_1.docx (48.2 KB)

Security_Cyber_Security_Information_Sharing_2.docx (57.6 KB)

Thank you @Rola .

I see a few items to be emphasized further:

  • AI agent for gathering & sharing information can solve language barriers between some countries (e.g. regarding one issue on JP Crypto ISAC side)
  • specific AI agent benefits: to ingest content & then to be able to share with limited leakage of info (private inference)
  • Incentives of actors to participate into info sharing remain a challenge
  • Language barrier is not only about natural language, but also about community/technical ones. Need for the use of standardized language to more easily communicate across organizations (C-suite vs grassroots).
  • Discussion of MITRE ATT&CK, AADAPT, D3FEND frameworks as a few to structure information and threat/controls mapping.
  • Participants interested to define some scenario that will see an increase in efficiency if relying on such common language in web3
  • Additional quick win: define a template for most valuable/key info to be shared for emergency support (preventive or incident response) and a process to obtain those info (in order to speed up compliance approval); and later run some experimentation for validating
  • A key quick win is indeed: definition of high value data elements to socialize the benefits & opportunities of sharing such info.

Additional comment: we now need to define how we will organize those activities. New cybersecurity WG calls soon?