<?xml version="1.0" encoding="UTF-8"?>
<PerformancePlanOrReport xmlns="urn:ISO:std:iso:17469:tech:xsd:PerformancePlanOrReport" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

 xsi:schemaLocation="urn:ISO:std:iso:17469:tech:xsd:PerformancePlanOrReport http://stratml.us/references/PerformancePlanOrReport20160216.xsd" Type="Strategic_Plan"><Name>Blockchain secure deployment 10-step process</Name><Description>When a sound business assessment has been made that blockchain technology is an appropriate tool to address a real business need, an organization must pay careful attention to critical success factors of deployment, including security considerations. This section provides a 10-step secure deployment guide to navigate users towards a successful security practice.</Description><OtherInformation>This white paper has been published by the World Economic Forum as a contribution to a project,
insight area or interaction. The findings, interpretations and conclusions expressed herein are a result of a collaborative process facilitated and endorsed by the World Economic Forum, but whose
results do not necessarily represent the views of the World Economic Forum, nor the entirety of its
Members, Partners or other stakeholders.</OtherInformation><StrategicPlanCore><Organization><Name>World Economic Forum</Name><Acronym>WEF</Acronym><Identifier>_de0af670-955b-11e0-9cc9-b0287a64ea2a</Identifier><Description/><Stakeholder StakeholderTypeType="Person"><Name>Adrien Ogée</Name><Description>Lead Author -- Lead, Technology and Innovation, World Economic Forum (Centre for Cybersecurity), Switzerland</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Soichi Furuya</Name><Description>Lead Author -- Senior Researcher, Hitachi (and World Economic Forum Fellow), USA</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Nadia Hewett</Name><Description>Lead Author -- Project Lead, Blockchain and DLT, World Economic Forum (Centre for the Fourth Industrial Revolution), USA</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Craig Chatfield</Name><Description>Contributor -- Blockchain Architect and Security Consulting Manager, Accenture, UK</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Dominique Guinard</Name><Description>Contributor -- Co-Founder and Chief Technology Officer, EVRYTHNG, Switzerland</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Francis Jee</Name><Description>Contributor -- Manager, Deloitte Consulting LLP (and World Economic Forum Fellow), USA</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Hanns-Christian Hanebeck</Name><Description>Contributor -- Founder and Chief Executive Officer, Truckl.io, USA</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Partha Das Chowdhury</Name><Description>Contributor -- Head, Blockchain CoE, VARA Technology, India</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Ramón Gómez-Ferrer</Name><Description>Contributor -- Head of Strategy and Innovation, Valencia Port Authority, Spain</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Sheila Warren</Name><Description>Contributor -- Head of Blockchain and DLT, World Economic Forum (Centre for the Fourth Industrial Revolution), USA</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Sumedha Deshmukh</Name><Description>Contributor -- Project Specialist, World Economic Forum (Centre for the Fourth Industrial Revolution), USA</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Jaka Mele</Name><Description>Commentator -- Chief Digital Officer, CargoX, Slovenia</Description></Stakeholder></Organization><Vision><Description>A successful security practice</Description><Identifier>_c24fa0a0-c20d-11ea-81f5-c5e6fd82ea00</Identifier></Vision><Mission><Description>To provide deployment guide for blockchain technology</Description><Identifier>_c24fa1a4-c20d-11ea-81f5-c5e6fd82ea00</Identifier></Mission><Value><Name>Trust</Name><Description>Digital trust is a prerequisite for blockchain technology to embrace its potential as a foundation of future international supply chain systems.</Description></Value><Value><Name>Expectations</Name><Description>Trust is derived from clear expectations.</Description></Value><Value><Name>Predictability</Name><Description>As such, digital trust stems from predictability – the knowledge that the
technologies we use will work as they should.</Description></Value><Value><Name>Security</Name><Description>Predictability, in turn, is enforced by security. </Description></Value><Goal><Name>Expertise</Name><Description>Acquire blockchain expertise</Description><Identifier>_c24fa262-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>Step 1</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Consortia</Name><Description>In the case of a consortium, for instance, it may be necessary to create a distributed security operations centre (SOC).</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Security Operations Centres</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Security Services</Name><Description>Given the recency of the technology’s development, only a limited number of third-party security services and training materials exist.</Description></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Blockchain Training Alliance</Name><Description>The landscape includes consulting firms and boutique companies as well as a few certification programmes, e.g. the Blockchain Security Professional certification of the Blockchain Training Alliance.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Cybersecurity Experts</Name><Description>It is worth noting that it may prove easiest to hire cybersecurity experts and train them in blockchain technology rather than doing the opposite.</Description></Stakeholder><OtherInformation>The first and probably most important step before considering a blockchain deployment is to acquire blockchain security talent. Depending on the company’s resources, and the criticality and objectives of the blockchain use case, this can range from outsourcing to a trusted third party to hiring or training staff with the necessary skills to oversee a secure deployment.
Ensuring the security of a blockchain solution over time requires qualified employees. Beyond business criticality, the degree of internalization of this expertise will depend on the blockchain type.</OtherInformation><Objective><Name>Oversight Teams</Name><Description>Create security oversight teams.</Description><Identifier>_c24fa352-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Security Oversight Teams</Name><Description>It is essential that this team has access to the highest security authority in the organization, be it the chief information security officer (CISO), the chief information officer (CIO) or even the board.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Chief Information Security Officers (CISO)</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Chief Information Officers (CIO)</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Consortia</Name><Description>If the blockchain is to be developed for a consortium, it is recommended that the security oversight team count on security staff from all organizations that are members of the consortium.</Description></Stakeholder><OtherInformation>End goal: the creation of a security oversight team that will be in charge of driving the next steps.</OtherInformation></Objective></Goal><Goal><Name>Goals</Name><Description>Define security goals</Description><Identifier>_c24fa406-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>Step 2</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>Port of Valencia</Name><Description>Importance of security objectives –
the Port of Valencia example -- 
The Port of Valencia recently commissioned a blockchain
solution to enable different entities working at the port
to share data in a much more efficient way. Before
developing a proof of concept, the leadership team
defined the following high-level security objectives,
among others:
– Data confidentiality is critical.
– The availability of the blockchain solution must be
better than what we currently have.
– We must be able to identify all entities participating in
the business network.
– The blockchain network must be compliant with the
General Data Protection Regulation (GDPR).</Description></Stakeholder><OtherInformation>A sound security culture within the organization, with a clear understanding of security goals, is a prerequisite for the secure deployment of a technology with so many grey zones. This evaluates the security posture and security goals of the entire organization, not just the blockchain use case.
A good starting place is the organization’s strategy, crisis management and business continuity policies. This step should answer some of the following questions:
– What are the major requirements of security from the CIA’s point of view, and how are they prioritized?
– Is it important to ensure full anonymity of the organization’s customers?
– How badly would the reputation of the organization be affected by an incident such as a system glitch or a data leak?</OtherInformation><Objective><Name>Requirements &amp; Priorities</Name><Description>Identify the major requirements of security from the CIA’s point of view, and how are they prioritized</Description><Identifier>_c24fa4c4-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Anonymity</Name><Description>Determine the importance of ensuring the anonymity of customers.</Description><Identifier>_c24fa582-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>2.2</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Customers</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Reputations</Name><Description>Evaluate how badly the reputation of the organization would be affected by system glitches or data leaks.</Description><Identifier>_c24fa6b8-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>2.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Plans</Name><Description>Outline the important goals in simple language.</Description><Identifier>_c24fa79e-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>2.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>End goal: a document outlining important goals in simple language. These answers will inform the risk assessment outlined in Step 4.</OtherInformation></Objective></Goal><Goal><Name>Blockchain Type</Name><Description>Choose the blockchain type</Description><Identifier>_c24fa870-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>Step 3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Depending on the business objectives and the security goals, choose which blockchain type would provide the best platform.
It is quite probable that the business rationale and functional specifications will inform this decision. While this is not security-by-design, it is the reality.
End goal: the creation of a document listing the security and business advantages and trade-offs of the various blockchain types considered.</OtherInformation><Objective><Name>Advantages &amp; Trade-Offs</Name><Description>List the security and business advantages and trade-offs of the various blockchain types considered.</Description><Identifier>_c24fa938-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>3.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Risk Assessment</Name><Description>Perform a risk assessment</Description><Identifier>_c24faa00-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>Step 4</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name>Port of Valencia</Name><Description>Threat and vulnerability assessment – Port of Valencia example -- To better understand the risks of the blockchain solution it was considering deploying, the Port of Valencia had the opportunity to assess the security risks of a blockchain solution during its proof of concept.
Examples of the main potential vulnerabilities identified
– The case where an attacker rewrites the ledger by
compromising a sufficient number of nodes. This will
put the business network at serious risk.
– The administrator’s secret key becomes accessible
to other parties, who can then impersonate the
administrator and even change the smart contracts.
– Node administrators are able to access confidential
data stored in the node.
– The administrator leaves the company.
Examples of the main potential threats
– A competitor in the business network with
administration rights to the node could be accessing
confidential data from other companies in the ledger.
– Someone with administration rights can access the
data stored in an external database in the node.
– Hacktivists could be drawn to the network.</Description></Stakeholder><OtherInformation>This step specifically concerns the blockchain use case to be developed. Please refer to Appendices 1 and 2 of this report, Blockchain risk management, and Key blockchain security risks, to perform the risk assessment...
End goal: a document listing all of the risks and the different management strategies chosen.</OtherInformation><Objective><Name>Actions</Name><Description>Compile a prioritized list of actions to manage the risks identified.</Description><Identifier>_c24faad2-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>4.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>This step should conclude with a prioritized list of actions to manage the risks identified.
In order to avoid using a partial and incomplete risk profile in a production environment, it is good practice to undertake this risk assessment as part of a proof of concept.</OtherInformation></Objective></Goal><Goal><Name>Security Controls</Name><Description>Define security controls</Description><Identifier>_c24faba4-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>Step 5</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation>Security controls may be able to reduce risks before these residual risks are transferred, avoided or accepted. Please refer to the mitigation strategies presented in Appendix 2 for ideas on defining these controls.
End goal: a document listing the security functional specifications of the blockchain and recommended security controls for the development team.</OtherInformation><Objective><Name>Functional Specifications</Name><Description>List the security functional specifications of the blockchain.</Description><Identifier>_c24fac76-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>5.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Security Controls</Name><Description>List the recommended security controls for the development team.</Description><Identifier>_c24fad52-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>5.2</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Blockchain Development Teams</Name><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Security Governance</Name><Description>Define security governance</Description><Identifier>_c24fae24-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>Step 6</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation>The security oversight team, structured in Step 1, is there to oversee the deployment of the blockchain solution, but not its long-term operation. As a result, it is critical for a governance structure and for processes to be defined prior to development kick-off. Once development starts, even a test version of the use case can be a source of security threats.</OtherInformation><Objective><Name>Risk</Name><Description>Base governance processes the degrees of risk.</Description><Identifier>_c24faf00-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>6.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>The governance processes will largely depend on the risks to be monitored. The more risks there are to manage, the more thorough the governance process will need to be.</OtherInformation></Objective><Objective><Name>Staffing</Name><Description>Base staffing on the security controls to be implemented and monitored.</Description><Identifier>_c24fafe6-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>6.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>The more security controls there are to implement and monitor, the more staff will be required.</OtherInformation></Objective><Objective><Name>Coordination</Name><Description>Coordinate appropriately with solution developers, operators, executive system owners and ecosystem participants.</Description><Identifier>_c24fb18a-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>6.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Blockchain Developers</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Blockchain Operators</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Blockchain  Ecosystem Participants</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Executive System Owners</Name><Description/></Stakeholder><OtherInformation>The more distributed the risks, the more coordination with solution developers, operators, executive system owners and ecosystem participants will be required.</OtherInformation></Objective><Objective><Name>Continuity &amp; Recovery Plans</Name><Description>Revise and update business continuity and disaster recovery plans as appropriate.</Description><Identifier>_c24fb27a-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>6.4</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation>End goal: revised business continuity and disaster recovery plans.</OtherInformation></Objective></Goal><Goal><Name>Vendors</Name><Description>Choose a secure vendor</Description><Identifier>_c24fb388-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>Step 7</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation>Choose the right security products and services, then evaluate vendors.
There are several established enterprise solutions out there, all offering some level of security service. In addition, boutique companies and consulting outfits can help.
End goal: one or more contracts with security vendors.</OtherInformation><Objective><Name/><Description/><Identifier>_c24fb478-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator/><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Security</Name><Description>Develop securely</Description><Identifier>_c24fb55e-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>Step 8</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation>Ensure that the developing team follows secure development practices, also known as DevSecOps, and in particular a secure software development life cycle (S-SDLC) methodology.
Secure SDLC ensures that security assurance activities such as penetration-testing, smart code auditing or architecture analysis are embedded in the development of the blockchain solution.
End goal: well-documented source code and planned security activities.</OtherInformation><Objective><Name>Penetration Testing</Name><Description>Embed penetration-testing in the development of blockchain solutions.</Description><Identifier>_c24fb662-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>8.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Code Auditing</Name><Description>Embed smart code auditing in the development of blockchain solutions.</Description><Identifier>_c24fb752-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>8.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Architecture Analysis</Name><Description>Embed architecture analysis in the development of blockchain solutions.</Description><Identifier>_c24fb838-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>8.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Monitoring &amp; Auditing</Name><Description>Monitor and audit security</Description><Identifier>_c24fba54-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>Step 9</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation>As explained in the first section, security is a process. New vulnerabilities are found, attackers become more creative, and thus security needs to be monitored actively...
End goal: active monitoring of the blockchain solution in the SOC.</OtherInformation><Objective><Name>Penetration Testing</Name><Description>Conduct regular penetration-testing of the infrastructure and applications.</Description><Identifier>_c24fbcf2-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>9.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>First, regular penetration-testing of the infrastructure and applications that interact with the solution is essential.</OtherInformation></Objective><Objective><Name>Contracts</Name><Description>Audit smart contracts.</Description><Identifier>_c24fbdf6-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>9.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Auditing of smart contracts is also required to ensure that no vulnerabilities exist in the smart contract code, or are introduced by the contract’s use. These penetration-testing and auditing processes should be ongoing and built into the blockchain solution’s operation out of the life cycle.</OtherInformation></Objective><Objective><Name>Security Operations Centres</Name><Description>Enable security operations centres (SOC) to monitor blockchain solutions along with other organizational assets.</Description><Identifier>_c24fbf86-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>9.3</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Security Operations Centres</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Consortia</Name><Description>There will be an increasing need for consortium blockchains to explore distributed SOCs, which are at present at the forefront of cybersecurity.</Description></Stakeholder><OtherInformation>Second, as previously covered, the security of a blockchain depends not only on the security of the blockchain itself but also on that of the underlying infrastructure that hosts the blockchain platform and solution components. As a result, it is highly recommended that you have a security operations centre (SOC) to monitor the blockchain solution along with the rest of the organization’s assets.</OtherInformation></Objective><Objective><Name>Audits</Name><Description>Periodically conduct audits to ensure security procedures and systems are up to date and best fitted to current systems and environments.</Description><Identifier>_c24fc094-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>9.4</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name/><Description/></Stakeholder><OtherInformation>To verify its effectiveness, an independent audit, either internal or external, is periodically conducted so that the provisions of these vital steps are up to date and best fitted to the current system and environment.</OtherInformation></Objective></Goal><Goal><Name>Incidents</Name><Description>Respond to incidents</Description><Identifier>_c24fc198-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>Step 10</SequenceIndicator><Stakeholder StakeholderTypeType="Organization"><Name/><Description/></Stakeholder><OtherInformation>Whenever security monitoring activities detect an incident, you need to be able to respond to the incident and attempt to mitigate any damage in a timely fashion...
End goal: timely mitigation of security incidents.</OtherInformation><Objective><Name>Post-Mortem Assessments</Name><Description>Conduct post-mortem assessments to improve the overall security posture and limit the risk of incidents reoccurring.</Description><Identifier>_c24fc2b0-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>10.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>After an incident occurs, it is essential to undertake a post-mortem assessment to improve the overall security posture of the solution and limit the risk of the incident reoccurring. Indeed, while incidents can be sources of disruption, they are also welcome opportunities to build the resilience of your blockchain and organization.</OtherInformation></Objective><Objective><Name>Security Plans</Name><Description>Integrate blockchain-specific procedures into security plans.</Description><Identifier>_c24fc3be-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>10.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>We believe there is no need to have blockchain-specific incident response plans or business continuity plans.  Blockchain is a technology like any other, and so it is wiser to integrate blockchain-specific procedures into the organization’s existing security plans.</OtherInformation></Objective><Objective><Name>Incident-Response Exercises</Name><Description>Conduct incident-response exercises.</Description><Identifier>_c24fc4c2-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>10.3</SequenceIndicator><Stakeholder StakeholderTypeType="Person"><Name>Heinrich Heine</Name><Description>Finally, in the words of the German poet Heinrich Heine: “Experience is a good school, but the fees are high.” </Description></Stakeholder><OtherInformation>It is of the utmost importance to conduct an incident-response exercise before such an event occurs.</OtherInformation></Objective><Objective><Name>Training</Name><Description>Training staff to respond to incidents.</Description><Identifier>_c24fc5e4-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>10.4</SequenceIndicator><Stakeholder StakeholderTypeType="Person"><Name/><Description/></Stakeholder><OtherInformation>Training staff to respond to such incidents and testing distributed decision-making processes is critical to managing real incidents and keeping blockchains secure.</OtherInformation></Objective><Objective><Name>Decision-Making Processes</Name><Description>Test distributed decision-making processes.</Description><Identifier>_c24fc6fc-c20d-11ea-81f5-c5e6fd82ea00</Identifier><SequenceIndicator>10.5</SequenceIndicator><Stakeholder StakeholderTypeType="Person"><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal></StrategicPlanCore><AdministrativeInformation><StartDate/><EndDate/><PublicationDate>2020-07-09</PublicationDate><Source>http://www3.weforum.org/docs/WEF_Inclusive_Deployment_of_Blockchain_for_Supply_Chains_Part_5.pdf</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></PerformancePlanOrReport>