The Supreme Committee for Delivery and Legacy (SCDL) issued this cyber framework to set a benchmark for all involved in the FIFA World Cup. The framework defines the core cyber competencies and capabilities needed to protect critical national services supporting the FIFA World Cup. Additional security and privacy concerns will arise as there will be more digital presence than ever. The Security Committee, with the help of many global partners, has developed the Qatar Cybersecurity Framework (QCF) to ensure a safe and secure event.
SCDL has taken a capability-based approach to defining the framework, considering the risks identified by different actors. This approach focuses on building the necessary capabilities to mitigate these increased risks. To determine the required capabilities, SCDL looked at core operational activities divided into layers surrounding the data that will apply to all systems. Ultimately, the framework identified 14 cybersecurity capabilities labelled into three pillars: prevention, detection, and response.
Implementation of the framework should follow a fairly simple process outlined by the SCDL, which recommends the following:
- Entities review the cybersecurity capabilities of the framework and map entity services to those capabilities.
- Independently evaluate the implementation of these capabilities and create a plan to address implementation gaps.
QCF – Requirements
- Map the entity’s critical information assets with defined cybersecurity capabilities in the framework
- Assess training gaps for cybersecurity capabilities
- Conduct post-training evaluation
- Measure current cybersecurity awareness levels in the entity
- Implement and enforce endpoint security configurations on the operating system, application and network layers
- Ensure that best practice security configurations are applied on endpoints
- Track asset inventory of endpoint devices
- Ensure that endpoint changes, patches and configuration through a controlled change management
- Install security applications on endpoint devices to ensure adequate protection is applied
- Identify, track and detect abnormal behaviours or malicious activities through incident handling
- Ensure endpoint protection is applied on hardware and software
- Test the application with the selected application security method
- The development and testing environments are separate from the production environment
- A baseline configuration of information technology/industrial control systems is created and maintained
- Network integrity is protected (e.g., network segregation, network segmentation)
- Configuration change control processes are in place
- Communications and control networks are protected
- Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
- A baseline of network operations, expected data flows for users and systems is established & managed
- Vulnerability scans are performed in collaboration with Security Monitoring and Operations
- Management and dashboard reporting of identified network configuration deviations.
- Event detection information is communicated to appropriate parties
- Physical and network access to assets is managed and protected
- Remote access of users and devices is managed
- Network integrity is protected (e.g., network segregation, network segmentation)
- Data-at-rest and Data-in-transit is protected
- Remote maintenance of assets is approved, logged, and performed to prevent unauthorized access
- Users, devices, and other assets are authenticated with the risk of the transaction
- Access permissions and authorizations are managed, incorporating the principles of least
- A baseline of network operations, expected data flows for users & systems is established and managed
- Vulnerability scans are performed in collaboration with Security Monitoring and Operations team
- Management and dashboard reporting of identified access control deviations
- Event detection information is communicated to appropriate parties
- Physical devices in the organization are inventoried, and external network systems are catalogued
- Adequate capacity to ensure availability is maintained
- Detected events from multiple sources and sensors are analysed to understand attack targets & method
- Maintenance and repair of assets are performed and logged, with approved and controlled tools
- Network Vulnerability scans are performed with the Security Monitoring and Operations team
- Network Audit/log records are determined, documented, implemented, and reviewed
- A recovery plan is executed during or after a cybersecurity incident
- Incidents and newly identified vulnerabilities are contained and mitigated
- Protect data based on its classification, with the highest protections for the most sensitive data
- Monitor all data movement to gain visibility into sensitive data
- Continuously improve and remediate identified errors and processes
- Secure communication channels for communicating change, configuration, and service outage
- Establish a process to notify stakeholders of breaches and downtime resulting from changes and patching
- Define authorization mechanisms to change, patch, and required configurations
- Establish a process to define, document and notify change, configuration, and patch deployment plans
- Log and track issues and risks associated with the changes, configurations, and patches
- Establish a process to capture, log, and report change, configuration, and patch deployment outcomes
- Security audit/log records are documented, implemented, and reviewed by the policy
- Detection activities comply with all applicable requirements
- Cyber threat intelligence is received from information-sharing forums and sources
- Event data are aggregated and correlated from multiple sources and sensors
- Malicious code is detected
- Unauthorized mobile code is detected
- Detected events are analysed to understand attack targets & methods; accordingly, triage is conducted
- Impact of events is determined
- Incident alert thresholds are established
- Monitoring for unauthorised personnel, connections, devices, and software is performed
- The network is monitored to detect potential cybersecurity events
- The physical environment is monitored to detect potential cybersecurity events
- Personnel activity is monitored to detect potential cybersecurity events
- Vulnerability scans are performed
- External service provider activity is monitored to detect potential cybersecurity events
- Event detection information is communicated to appropriate parties
- Detection processes are continuously improved
- Automate the collection to a central logging system ( within layer 3 as per the ISA99/IEC62443 model)
- Fine-tune the collected logs and apply techniques such as linking the OT asset management system
- Automate a process of collecting IOCs and threat intelligence
- Subscribe to and collect threat feeds from public and community sources (free as well as commercial)
- Set up use cases and rules as per planned policies
- Ingest OT IOCs and Attack signatures
- Investigate alerts and conduct triage
- Analyse deviations from the agreed network baseline (Cyber analytics)
- Analyse new OT threat feeds and verify applicability to your systems and environment
- Escalation of alerts
- OT Incident containment and management in alignment with operational and plant safety requirements
- Reporting channels horizontally and vertically
- Vendor secure communication
- Incident Response plans are prepared, in place and managed
- Define a secure way of communication, such as encryption software, among stakeholders
- Response and recovery plans are tested
- Events are reported consistent with established criteria
- Notifications from detection systems are investigated, and conduct triage is conducted
- An Incident Response plan is executed during or after an event
- Incidents are categorized and assigned a criticality level consistent with response plans
- The impact of the incident is understood
- Malicious code is detected, which has been identified as a part of the analysis
- Forensics are performed, where required, after getting authorization approval from management
- Newly identified vulnerabilities are mitigated or documented as accepted risks
- Mechanisms to monitor and quantify the types and volumes of cyber security incidents
- Processes are established to receive, analyse and respond to
- Evaluation and identification of improvements in recovery and continuity capability.
- Review of Recovery and Continuity program against established Performance matrices and KPIs
- Keep records regarding data processing
- Implement controls to protect personal data to prevent and detect data attacks and breaches
- Conduct periodic audits and performance reviews of the Privacy Management Framework
- Manage identities of users during onboarding, transfer, and off-boarding across platforms
- Unique ID generation
- Identity profile management
- Establish processes and tools to create, modify, delete and monitor user accounts and entitlements
- Provisioning Workflow (On-Board, Move/Update, Revoke)
- Privileged access management
- Credential management (Password Management)
- Role management: access based on job functions/responsibilities and related permissions
- Fine-grained access policy administration
- Processes and tools used to control users’ access to protected
- Identity federation
- Fine-grained access policy enforcement
- Log consolidation and analysis
- Identity and access monitoring
- Privileged access monitoring
- Processes and tools to understand the health of the various IAM components
- Identify opportunities for improvement in processes
- Provide evidence for access reviews, audit activities
- Policy compliance monitoring
- Role and definition certification
- Authentication of management and monitoring assets Maintaining the integrity of logs and reports
- Holistic assessment of data integrity in its lifecycle across the entire IoT system
- Encrypted data storage and communication
- Architectural confidentiality evaluation; Enforcing principle of least privilege; Access control
- Sandboxing; Fine-grained data- centric access control; Separation kernels; Trusted computing
- Access control for monitoring, logging and managing assets; Control procedures for managing and monitoring operations; Controlling access to data fed into analytics solutions and RBAC
- Removing unnecessary software apps
- Disabling or removing unnecessary usernames, Crede, rentals, services and ports
- Applying security and functionality patches (operating system and all approved applications)

