The voluntary cyberthreat information-sharing groups (ISAOs) would have to meet certain baseline standards and would be able to seek third-party certification of their capabilities under a proposal unveiled Wednesday. Third-party verification is essential for scalability of trusted information-sharing, explained Gregory White, executive director of the Information Sharing and Analysis Organization Standards Organization, or ISAO-SO. “When we have thousands of ISAOs out there, how the heck do I know who I can trust?” asked White, a University of Texas San Antonio computer science professor. He compared certification to the security clearance individuals need to access classified information. “Because you have that clearance, I know certain things about you have been verified by a trusted third party … I know I can trust you with certain kinds of information,” he said, adding it was a scalable alternative to developing face-to-face or individual trust relationships. But he acknowledged the move would prove controversial among ISAOs, […]
The post New certification planned for industry information sharing orgs appeared first on Cyberscoop.
Continue reading New certification planned for industry information sharing orgs→