Last year, Bitsight was proud to help drive the Principles for Fair and Accurate Security Ratings, published by the US Chamber of Commerce and supported by over 40 global organizations. The establishment of these Principles demonstrates the momentum and maturity of the security ratings market that Bitsight pioneered in 2011. The Principles were designed to promote fairness in reporting of cybersecurity performance and encourage the adoption of security ratings across all industry sectors.
One of the important aspects the US Chamber of Commerce highlights is Confidentiality, which we refer to as Responsible Disclosure. Essentially, every security ratings company is obligated to not publicize company ratings and keep all sensitive information confidential to the party to which that sensitive information is attributed. The purpose of the Principles and Responsible Disclosure is to not only earn, but to also maintain, the market’s trust in this new category of ratings. At Bitsight, we take this responsibility very seriously.
Bitsight, along with three other security ratings companies, signed on to these Principles, therefore committing to adhere to the tenets. However, some are now rationalizing the Confidentiality Principle in an effort to justify the public disclosure of companies’ ratings and share sensitive security data with organizations other than the company to which it relates. There are several reasons why it is not in the best interest of this market’s maturity for ratings companies to publicize a company’s rating, and further, why it is truly irresponsible to broadly expose sensitive security information about a company.
The Difference Between Trust and Transparency
In the Chamber of Commerce’s official release, they list Confidentiality as one of the six official Principles for Fair and Accurate Security Ratings. By working with companies like Bitsight to publish these guidelines, the Chamber of Commerce’s objective was to establish a baseline by which all participatory companies must abide.
The Principles for Fair and Accurate Security Ratings included the following requirements within Confidentiality: “Information disclosed by a rated organization during the course of a challenged rating or dispute shall be appropriately protected. Rating companies should not publicize an individual organization’s rating. Rating companies shall not provide third parties with sensitive or confidential information on rated organizations that could lead directly to system compromise.”
There is no ambiguity to “Rating companies should not publicize an organization's rating.” Ratings companies who have signed onto the Principles and publicize a company’s rating violate this commitment. Rationalizing this action through an argument that the underlying data is available (and therefore, this is about transparency) doesn’t justify violating a commitment that many organizations worked hard to collectively agree to. As is almost always the case in matters of sensitivity, transparency can violate trust. At Bitsight, we’re firm believers in transparency. We have a comprehensive dispute resolution process, which reflects our desire to be transparent with the appropriate party and information. In matters of sensitivity, judgement in what can be shared (and with whom) is a crucial step in building trust with all parties. Broad transparency of this sensitive data violates trust. Even worse, simply publishing information without context does not meet the test of transparency. In the case of security ratings, it hurts the overall advancement of the market.