We introduce the Coverage Gap as a measurable distance between the observable public exposure of critical-infrastructure operators and their declared capability to coordinate vulnerability disclosure. We instantiate it against the 915 Chilean Operadores de Importancia Vital (OIVs -- Operators of Vital Importance) designated by the National Cybersecurity Agency (ANCI) under Ley 21.663 (Resolucion Exenta No. 87, 16 December 2025). Using a passive-only, OSINT-based method consistent with the principles of ISO/IEC 29147:2018 and Chile's computer-crimes safe harbour (Ley 21.459), we conduct a full-universe census of the foundational disclosure-capability layer (Layer 1, verifiable disclosure contact) across approximately 98.7% of the official catalogue. Only 16 of 915 OIVs (1.7%) publish a verifiable RFC 9116 disclosure channel; among operators of physical-world infrastructure -- energy, health, banking, telecommunications, fuel, water, transport, and state administration -- fewer than ten do so, and all four major banks and both telecommunications incumbents lack one entirely. This compares with over 99% adherence in the U.S. federal civilian branch under CISA Binding Operational Directive 18-01. Email-authentication misconfiguration affects 766 of 915 (84%) OIVs, and end-of-life or known-vulnerable stack components an estimated 23.5% (Wilson 95% CI [12%, 38%]). Cross-jurisdictional benchmarking situates Chile roughly eight years behind the USA, the UK, and the Netherlands on email-authentication mandates, and three years behind Denmark. We propose a four-stage roadmap modelled on BOD 18-01 and the UK Public-Sector DMARC Toolkit, and release the open-source tool anci-oiv-resolver (Apache 2.0) to enable independent reproduction of the OIV-domain mapping that underpins universe-scale auditing.
翻译:我们引入“覆盖缺口”这一概念,将其定义为关键基础设施运营者可观察的公众暴露程度与其所宣称的漏洞披露协调能力之间的可衡量差距。我们以智利国家网络安全局(ANCI)根据第21.663号法律(第87号豁免决议,2025年12月16日)指定的915家“关键重要性运营者”(OIVs)为实例进行验证。采用一种仅基于被动方法、符合ISO/IEC 29147:2018原则及智利计算机犯罪安全港(第21.459号法律)的开源情报(OSINT)方法,我们对基础披露能力层(第一层,可验证的披露联系人)进行了全量普查,覆盖了约98.7%的官方目录。在915家OIV中,仅有16家(1.7%)发布了可验证的RFC 9116披露渠道;在实体基础设施领域的运营者(能源、医疗、银行、电信、燃料、水务、交通及国家行政管理)中,少于10家做到这一点,而所有四大主要银行及两家现有电信运营商均完全缺失此类渠道。相比之下,根据网络安全和基础设施安全局(CISA)约束性操作指令18-01,美国联邦民事部门的合规率超过99%。电子邮件认证配置错误影响了915家OIV中的766家(84%),而使用生命周期终止或已知存在漏洞的堆栈组件的比例估计为23.5%(Wilson 95%置信区间[12%, 38%])。通过跨司法管辖区基准比较,智利在电子邮件认证强制要求方面落后于美国、英国和荷兰约八年,落后丹麦约三年。我们提出一个以BOD 18-01及英国公共部门DMARC工具包为蓝本的四阶段路线图,并发布开源工具anci-oiv-resolver(Apache 2.0许可证),以支持独立复现支撑全量审计规模的OIV域名映射。