Critical Terminology Foundations
Total Page:16
File Type:pdf, Size:1020Kb
ISSUE 2 ISSUE 2 NOVEMBER 2013 RUSSIA-U.S. BILATERAL ON CYBERSECURITY CRITICAL TERMINOLOGY FOUNDATIONS 2" EASTWEST INSTITUTE MOSCOW STATE UNIVERSITY WORLDWIDE CYBERSECURITY INITIATIVE INFORMATION SECURITY INSTITUTE 1 ISSUE 2 November 2013 RUSSIA-U.S. BILATERAL ON CYBERSECURITY CRITICAL TERMINOLOGY FOUNDATIONS The Russia-U.S. Bilateral on Cybersecurity – Critical Terminology Foundations, Issue 2 The principle editors of this document are: James B. Godwin III, Andrey Kulpin, Karl Frederick Rauscher and Valery Yaschenko Cover artwork by Dragan Stojanovski. ISBN No. 978-0-9856824-4-6 Copyright © 2013 EastWest Institute and the Information Security Institute of Moscow State University The EastWest Institute is an international, non- Information Security Institute was founded as a partisan, not-for-profit policy organization focused separate department of Moscow University in 2003. solely on confronting critical challenges that endanger The main aim of the Institute is to coordinate the peace. EWI was established in 1980 as a catalyst to research activity in the Moscow University, which build trust, develop leadership, and promote deals with information security. For more information collaboration for positive change. The institute has about the Information Security Institute, please offices in New York, Brussels, and Moscow. For more contact: information about the EastWest Institute or this paper, please contact: The EastWest Institute Information Security Institute 11 East 26th Street, 20th Floor Moscow State University New York, NY 10010 U.S.A. Michurinskiy prospeky, 1 1-212-824-4100 Moscow, RUSSIA, 119192 [email protected] 7 495 932-8958 [email protected] www.ewi.info www.iisi.msu.ru EASTWEST INSTITUTE MOSCOW STATE UNIVERSITY WORLDWIDE CYBERSECURITY INITIATIVE INFORMATION SECURITY INSTITUTE 2 ISSUE 2 NOVEMBER 2013 RUSSIA-U.S. BILATERAL ON CYBERSECURITY CRITICAL TERMINOLOGY FOUNDATIONS RUSSIA-U.S. BILATERAL ON CYBERSECURITY CRITICAL TERMINOLOGY FOUNDATIONS II JAMES B. GODWIN III, ANDREY KULPIN, KARL FREDERICK RAUSCHER & VALERY YASCHENKO Chief Editors Институт Восток-Запад Information Security Institute EASTWEST INSTITUTE MOSCOW STATE UNIVERSITY WORLDWIDE CYBERSECURITY INITIATIVE INFORMATION SECURITY INSTITUTE 3 ISSUE 2 NOVEMBER 2013 RUSSIA-U.S. BILATERAL ON CYBERSECURITY CRITICAL TERMINOLOGY FOUNDATIONS Dedication To those pioneers of the Russia-American relationship during the last half century, who have avoided an unspeakable conflict. EASTWEST INSTITUTE MOSCOW STATE UNIVERSITY WORLDWIDE CYBERSECURITY INITIATIVE INFORMATION SECURITY INSTITUTE 4 ISSUE 2 NOVEMBER 2013 RUSSIA-U.S. BILATERAL ON CYBERSECURITY CRITICAL TERMINOLOGY FOUNDATIONS Foreword Earlier this year Presidents Vladimir Putin and Barack Obama signed a historic agreement to begin cooperation on cybersecurity. Those engaged in that process noted that the previous Track 2 work undertaken by our institutions in 2011 to define critical terminology for cyber conflict (Critical Terminology Foundations: Report #1 - download text at www.ewi.info) was instrumental in that agreement coming about. We are also pleased with the international recognition of that work and the call for continuing definitional work by the 2012 United Nations Group of Governmental Experts (GGE). Meetings in India, China, and Europe have been convened to discuss our first report thus broadening the reach of the report. Since our 2011 report was issued, both of our countries and the world have witnessed an increasing need for new 'rules of the road' for cyberspace. Ultimately, the essential building blocks for any international agreements are words that convey the same meaning to each party involved. Cyberspace is unlike any other subject in history in the degree of its complexity, the speed of its advance and its nature of carrying so many key concepts that are too often beyond the grasp of the non-technically trained diplomat. Our institutions are fortunate to once again have at the helm for this study a world-class team of science, technology, engineering and mathematics (STEM) professionals integrated with stakeholders with military, policy and legal training. This report based on superb teams from our two nations working together in a Track 2 process has yielded another 20 terms. We present this report a small but necessary step in making this world a safer place for all of us. ! __________ _ JOHN EDWIN MROZ VLADISLAV P. SHERSTYUK President & CEO Director, Information Security Institute EastWest Institute Moscow State University EASTWEST INSTITUTE MOSCOW STATE UNIVERSITY WORLDWIDE CYBERSECURITY INITIATIVE INFORMATION SECURITY INSTITUTE 5 ISSUE 2 NOVEMBER 2013 RUSSIA-U.S. BILATERAL ON CYBERSECURITY CRITICAL TERMINOLOGY FOUNDATIONS Preface Twenty terms were established through our initial bilateral negotiations and publication in April 2011. The joint team reinitiated efforts to build on that foundational work, to further define critical terms and build on the collaborative relationship, which was established. As the worldwide rhetoric has continued to escalate in the Cybersecurity Domain, the fundamental tenets of a common set of language continued to rise to the surface of any conversation. With increasing frequency of incidents occurring, unattributable accusations within and outside of borders, and expanding use of Networked Systems to probe systems worldwide, there is an ever-growing need to check the escalation of these intrusions and establish norms by which we can multilaterally agree. While this effort was bilateral in nature, the overriding intent is for these efforts to take on a tenor of a multilateral agreement and expand the inclusiveness to all those that seek to more clearly come into agreement and alignment on what has clearly been an ill-defined and unstructured free play arena. The teams have contributed greatly both in their individual compilation, bilateral negotiations, collaboration, consensus and most importantly in the ever growing trust relationship that has grown from our initial efforts in 2011. While this superficially represents 20 additional agreed to terms, the robust, substantive and ongoing nature of these negotiations is building on the foundation, which is required for recurring bilateral discussions beyond the bounds of terminology to those of establishing accepted worldwide standards in the Cyber and Information Domains. There continues to be opinion surrounding the meaning and intent of these terms for which there will always be grounds for improvement, but the bold steps of venturing out and placing something from which to deviate and expound upon is always before the readership. We both welcome and encourage comment, opinion and correction as deemed necessary. This set of terms is being presented at the 4th Worldwide Cyberspace Cooperation Summit in Palo Alto, CA, USA in November 2013, as an addendum to the original document. Our intention is to make these efforts an ongoing and expanding universe of agreed to terms without defining a scope or set of limitations. Join us in this journey! RADM(ret) JB Godwin III Andrey Kulpin Leader, US Experts Leader, Russia Experts President, BriteWerx, Inc. Director of International Center & Senior Fellow Information Security Institute EastWest Institute Moscow State University New York City, NY, USA Moscow, Russia EASTWEST INSTITUTE MOSCOW STATE UNIVERSITY WORLDWIDE CYBERSECURITY INITIATIVE INFORMATION SECURITY INSTITUTE 6 ISSUE 2 NOVEMBER 2013 RUSSIA-U.S. BILATERAL ON CYBERSECURITY CRITICAL TERMINOLOGY FOUNDATIONS Contributors1 Russian Federation Vladimir Ivanov, EastWest Institute Sergey Komov, Information Security Institute* Andrey Kulpin, Information Security Institute Alexey Salnikov, Information Security Institute Anatoliy Streltsov, Information Security Institute Valery Yaschenko, Information Security Institute United States of America Merritt Baer, PLC** Charles (Chuck) Barry, National Defense University John S. Edwards, Digicom, Inc.* J. B. (Gib) Godwin III, RADM (ret.), BriteWerx, Inc. and EWI Sr. Fellow Stuart Goldman, Bell Labs Fellow (ret.) Luis Kun, National Defense University** Paul Nicholas, Microsoft Corporation* James Bret Michael, U.S. Naval Postgraduate School* Jack Oslund, George Washington University (ret.) Karl Frederick Rauscher, EastWest Institute, Bell Labs Fellow *Issue I contributors only **Issue II contributors only Special appreciation is expressed here for Nadiya Kostyuk for her broad research and translation support for the team. 1 Please see the biographies section for a short background of each of the primary contributors. 2 The constructions “cyber and information security” and “information and cyber security” were agreed to by the combined team to EASTWEST INSTITUTE MOSCOW STATE UNIVERSITY WORLDWIDE CYBERSECURITY INITIATIVE INFORMATION SECURITY INSTITUTE 7 ISSUE 2 NOVEMBER 2013 RUSSIA-U.S. BILATERAL ON CYBERSECURITY CRITICAL TERMINOLOGY FOUNDATIONS Acknowledgements Special recognition and sincere appreciation is here expressed to Vartan Sarkissian and Vladimir Ivanov, for their vision and persistence in opening the door for this opportunity. to Anatoly Safonov, Vladislav Sherstyuk, Andrey Krutskikh, and John Edwin Mroz, for their foresight and encouragement of such Track 2 Russian-American cooperative efforts on the most challenging global security problems. and finally, to our wider community of respective stakeholder confidants in Moscow, Washington, D.C. and around the world, whose appreciation for innovation in Track 2 engagements ensures the work’s long-term value. EASTWEST