夥伴利害關係人

國際組織利害關係人

此次利害關係人調查包括四位來自國際組織-ICANN、APNIC和國外CERT的管理階層和合作窗口,雖然三個組織與中心的合作業務有差異,考量到國際組織的建議角度一致,且皆有國外經驗帶入台灣的分享,在訪談整理時歸納為同一類利害關係人,即國際組織。

組織現況與合作關係

國際組織的利害關係人對於TWNIC和TWCERT/CC合作現況皆表示互動密切良好,並感謝持續對國際社群積極投入。利害關係人認為TWNIC為推展政策或技術強而有力的夥伴,在執行長積極主動的領導風格下厚植技術互動基礎、完善網路穩定與安全基礎。

The thing that they're part of those are working group activities and we really appreciate those contribution from TWCERT in terms of those working group activities and things like that so I would expect there I look forward to their continuous contribution to those working groups and APCERT activities.

I think TWNIC has always been one of the leaders in helping to establish better practices, new services and technologies and so forth so this despite a little bit quite a lot of technical development going on at the moment.

利害關係人對於活動辦理上也給予高度評價,肯定持續辦理活動、不因疫情而中斷,積極促動協力參與、維繫國內外互動聯繫,在活動溝通上順暢,並且驚艷於中心在疫情下創新的混合辦理模式,使國際夥伴留下深刻印象。

That event was actually the first sort of a hybrid event that we actually manage to have with fellow collaborators, so it was kind of like a bit of a milestone for us because I think before that all the other events, we were able to do that they were either smaller scale or they would just be online. So that forum actually in April was the first one that we actually really did something that's like a full on like forum and it's in a hybrid mode.

重點發展領域建議

國際組織利害關係人在合作進展與建議上,除了延續現有技術領域資源、教育訓練支援和註冊業務等深化基礎合作外,並持續挹注資源,分享更多台灣資源和經驗給國際。實務上可以善用大眾傳播媒體增加曝光度,利用不同的內容形式連結更多的受眾,例如在活動後透過重點剪輯影片,讓沒有空參與活動的人可以觀賞影片後,很快得到重點資訊等。

So that sort of like, exposure to the community, not only to the technical community but also to the wider general users... exposure is one of the approaches to, but there is no quick solution to this question. So you have to work on it for a long time, I think it takes a while for people to actually get an understanding of organization and like getting trust so it's not an easy solution.

So we had to do the events, but if you want to engage your wider audience, then we have to work in building in content that is in bite sizes through today's audience's attention span, because people would follow you for one hour they will just do it for like maybe 10 minutes they will jump on, but only the things that are relevant for them.

同時持續使用不同語言來搭建國際溝通橋樑,也是發展更多國際社群互動機會的基礎。

I didn't recall many publications are made in English so I think in terms of reaching out to more wider audience or partners, I guess, pumping up more about English publication of forms or like advisories. I think they're doing quite good technical capability as well so I guess that's that part might be one of the, you know, One of the ways to actually increase their engagement, more audience.

組織未來定位與期許

在目前推動國內外組織連結與耕耘在地社群受到肯定下,利害關係人仍鼓勵在組織未來定位和期許是繼續發展國際關係,活絡在地社群、促進國內外網路社群的連結。

I think we're also like quite grateful that TWNIC that they have a lot of good ideas to try and facilitate that sort of the interaction with the people who are in Taiwan.

他們可以多鼓勵台灣業界或是深入校園更接觸一些 younger generation (年輕世代)去參與網路治理跟管理這一塊,畢竟他們在台灣在地有比較緊密連結,他可以再更深入它們的 local community (在地社群)帶到 APNIC 我覺得會是更好的一個努力方向。

利害關係人也提出TWNIC得天獨厚的政府與民間橋樑角色,加上維運TWCERT/CC的優勢,建議協助輔導其他國家設立CERT,以技術輸出拓展國際社群,深植台灣技術實力特色並建立國際信任,增加國際影響力、並獲得更多話語權的機會。

CERTs come in a lot of different flavors and knowing, and from the excessively governmental and bureaucratic national security oriented to something much more practical and hands on. My understanding of TWCERT that had some gifts in the middle but towards the practical end, I think the way of TWNIC has always been a very pragmatic and practical hands on sort of approach and that also that also potentially gives a role in providing services elsewhere and we has been helping with the establishment of certs in small Pacific Island places where a CERT is literally a couple of people employed to do that and they've got a huge job because they are looking after relations with government, police and NGOs, sort of non government sector in business and everything. So, that possibly that potentially is a role for TWNIC and one where we could certainly have a collaboration so that that the ability to create the necessary human relationships and to extend the circles of trust, which are really important in the surf community through that and build it on a technology transfer sort of relationship is quite huge.

政府單位

根基穩固完整,期許積極提升品牌知名度與價值

利害關係人認為TWNIC和TWCERT/CC定位根基穩固,擔任政府協助要角且表現符合期待,今年的願景希望能看到TWCERT/CC在原有服務上有更卓越蓬勃的發展。

我先講TWNIC在過去這一年還不錯,針對一些像最近賭博式的網站,這些都可以提出具體建議,最近在做RPZ也可以給政府機關一些回覆,他們在處理通報不合法或灰色網頁是執行主力,這樣的角度可以避免一般民眾被詐騙,我覺得表現滿好。

相關成果符合政府對TWCERT/CC的期待,也期待TWCERT/CC能有更多更積極的作為,政府也會提供更大的助力。整體框架有了,重點就在於持續做深、做廣。

利害關係人同時也肯定TWCERT/CC的努力付出,包括資安事件通報協處、情資分享和資安素養教育等,同時也展望下一步希望能繼續提升品牌知名度,讓更多的人、公司、產業來認識TWCERT/CC,積極推動相關服務內容和宣傳,發揮更大影響力。

具體的作法如掌握疫情阻力化為行銷助力,包括目前官網提供的遠距辦公資安專區等,彙整相關資訊提供給使用者,或藉由社群媒體的高使用率接觸更多受眾,擴大行銷宣傳獲得更多關注,打造品牌知名度、奠定品牌價值。

疫情對TWCERT/CC是最好的機會,一般民眾居家辦公的建議,視訊會議的建議,逐漸地累積就是會讓大家記得。

這些專區成立和內容的製作,都是厚植企業資安認知及強化企業資安事件處理能量的積極作為。這些知識需要更多的推廣與宣導,需要與更多的單位合作協助推動,才能發揮更大的影響力。

關注國際資安與網路發展趨勢,部署資安規格標準

利害關係人建議關注國際資安趨勢和最新網路應用發展,從中找到服務契機,進而發掘服務缺口和對象,建議TWCERT/CC以技術實力加上產業、政府三方互動密切的角色,協調各項新科技的在網路安全上的發展。

持續關注國際資安趨勢,就能知道這些新興應用服務的資安趨勢及發展,而且新興應用服務絕大多數非資通安全管理法所指特定非公務機關,因此這些都是TWCERT/CC的服務對象。

隨著5G、AIoT、網路平台IP化等科技發展,各種創新應用服務也因應而生。這些應用不管是多麼的創新,為持續發展,資安防護必不可少,這也就到了TWCERT/CC最擅長的領域。

持續檢視工作成效,橫向串聯、向下扎根、跨界合作

利害關係人以為TWCERT/CC特有的公私領域橋接角色,期待在國內產官學之間能發展更多元密切的互動關係,先透過檢視現有的服務,了解使用對象並且擴大服務價值。透過不同組織間跨界合作的形式,橫向串聯相同性質的資安單位、資安公司,向下扎根促進民眾的資安素養、結合企業資安需求,並且透過跨界合作,結合學術研究和官方檢調資訊分享,借力使力,打造更嚴密的資安防護網。

TWCERT/CC有可能扮演去公司內部去做協助協處的角色,這從資訊分享、資訊提供到顧問的角度,這是我自己一些發想。或許是跟資安業者合作,或資安業者自己去做,或要找TWCERT/CC才要著力點,這要思考。

TWCERT/CC畢竟資源有限,人力有限,所以應該要更重視與各界的合作,借由產、官、學、研的力量.。未來可藉由與公協會等,辦理資安通報及應變處理研討會、資安情資分享會議及經營TWCERT/CC社群網站進行宣導及推廣,建立雙方間的信任關係。

Copyright© 財團法人台灣網路資訊中心