Introduction
This document outlines the Terms of Reference for the European Railways Information Sharing and Analysis Center (Rail-ISAC.EU), aimed at enhancing cybersecurity resilience across European Railways. Rail-ISAC.EU is independent and was built by the rail sector, for the rail sector without involvement of any third-party entities or government bodies. This setup allows critical security information and data to be shared openly among members, fostering greater trust and lowering the threshold for sharing sensitive information.
Objectives
- To facilitate timely sharing of cybersecurity information, threats, and vulnerabilities related to European Railways.
- To provide analysis and expertise on cybersecurity incidents, threats, and trends.
- To foster collaboration and coordination amongst European Railway entities for enhancing cybersecurity preparedness and response.
Scope
- Rail-ISAC provides a forum to exchange cyber security related information between experts.
- Rail-ISAC provides a Threat Intelligence system to exchange structured information regarding indicators of compromise and observables.
- Rail-ISAC covers cybersecurity aspects of railway operations, infrastructure, data management, and related IT and OT systems across Europe.
Membership
- Membership is open to European Railway operators and infrastructure managers.
- Membership is free of charge.
- Members are required to actively contribute to information sharing and adhere to the protocols and confidentiality requirements of the Rail-ISAC.
- Membership is allowed for in-house employees only; no external providers (e.g. MSSP, MDR etc.) are allowed.
- Railways may send as many in-house experts to participate in Rail-ISAC as they wish; there is no hard limit for participants.
- An official company e-mail address is required to access Rail-ISAC; no personal or private e-mail addresses will be accepted for members.
- Membership may be terminated if a member fails to make a recognizable contribution to Rail-ISAC over an extended time period or if a member violates the Terms of Reference.
Access Policies
- Members are required to use strong authentication methods like multi-factor authentication or FIDO2.
- Members are required to choose strong passwords for Rail-ISAC.
- Members should access Rail-ISAC only from trusted devices.
Governance & Liability
The Rail-ISAC will be governed by an internal committee led by Deutsche Bahn. The committee will be responsible for setting policies, overseeing activities and ensuring adherence to the ToR.
As operator of the Rail-ISAC, DB strives to provide the platform to the best of their knowledge and in compliance with current IT security standards. However, DB doesn't accept any liability for incidents, damages, or losses that may arise directly or indirectly from the use of this platform.
By using this forum, you acknowledge and agree that the platform is provided "as is," without warranties of any kind, either express or implied.
Information Sharing Protocol
Information sharing will be conducted through the forum or the threat intelligence system and in accordance with established TLP protocols to ensure confidentiality and integrity.
Confidentiality and Data Protection
- All systems of Rail-ISAC are run by Deutsche Bahn CSIRT; all data is kept confidentially on systems which are in full control of Deutsche Bahn CSIRT.
- All members must commit to maintaining the confidentiality of shared information according to the TLP classification.
- If information needs to be shared with contracted service providers like MSSP, MDR etc., members shall ensure that their service providers fully comply with Rail-ISAC's TLP Protocol. Compliance with the EU General Data Protection Regulation (GDPR) is mandatory.
Meetings and Communication
- Ad-hoc virtual meetings can be organized for information exchange, incident analysis, and coordination of joint initiatives in case of major events.
- The Rail-ISAC forum will be used for continuous communication and alerts.
Review and Amendments
These Terms of Reference will be reviewed annually.