当前位置:首页 >英文主页 >中英对照 > 报告详情

CISA:2024运营技术网络安全原则指南(英文版)(14页).PDF

上传人: 白**** 编号:178865 2024-10-25 14页 1.74MB

下载:

1、Content Complexity MODERATEPrinciples of operational technology cyber securityThis publication was developed by the Australian Signals Directorates Australian Cyber Security Centre(ASDs ACSC)in collaboration with the U.S.Cybersecurity and Infrastructure Security Agency(CISA),National Security Agency

2、(NSA),Federal Bureau of Investigation(FBI),Multi-State Information Sharing and Analysis Center(MS-ISAC),United Kingdoms National Cyber Security Centre(NCSC-UK),Canadian Centre for Cyber Security(Cyber Centre),New Zealands National Cyber Security Centre(NCSC-NZ),Germanys Federal Office for Informatio

3、n Security(BSI Germany),the Netherlands National Cyber Security Centre(NCSC-NL),Japans National Center of Incident Readiness and Strategy for Cybersecurity(NISC)and National Police Agency(NPA),and the Republic of Koreas National Intelligence Service(NIS)and NIS National Cyber Security Center(NCSC).P

4、rinciples of operational technology cyber security3ContentsIntroduction 4Principles of operational technology cyber security 5Principle 1:Safety is paramount 5Principle 2:Knowledge of the business is crucial 6Principle 3:OT data is extremely valuable and needs to be protected 8Principle 4:Segment an

5、d segregate OT from all other networks 9Principle 5:The supply chain must be secure 11Principle 6:People are essential for OT cyber security 12IntroductionCritical infrastructure organisations provide vital services,including supplying clean water,energy,and transportation,to the public.These organi

6、sations rely on operational technology(OT)to control and manage the physical equipment and processes that provide these critical services.As such,the continuity of vital services relies on critical infrastructure organisations ensuring the cyber security and safety of their OT.Due to the extensive i

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文由澳大利亚信号局澳大利亚网络安全中心(ASD's ACSC)与美国网络安全和基础设施安全局(CISA)、国家安全局(NSA)、联邦调查局(FBI)、多州信息共享和分析中心(MS-ISAC)、英国国家网络安全中心(NCSC-UK)、加拿大网络安全中心(Cyber Centre)、新西兰国家网络安全中心(NCSC-NZ)、德国联邦信息安全办公室(BSI Germany)、荷兰国家网络安全中心(NCSC-NL)、日本国家事件准备和网络安全战略中心(NISC)和国家警察局(NPA)、韩国国家情报院(NIS)和NIS国家网络安全中心(NCSC)共同开发,旨在帮助关键基础设施组织设计、实施和管理运营技术(OT)环境,确保其既安全又可靠,并支持关键服务的业务连续性。 文章提出了六个原则来指导创建和维护一个安全、可靠的运营技术环境: 1. 安全至上:在物理环境中,安全至关重要。运营技术系统的领导者必须考虑到生命威胁,并在日常决策中进行权衡。 2. 业务知识至关重要:了解自己的业务,可以帮助企业更好地防范、准备和应对网络事件。 3. 运营技术数据极具价值,需要保护:运营技术数据,包括工程配置数据和瞬时运营技术值,对恶意行为者具有吸引力,因此需要保护。 4. 运营技术与其他网络隔离:运营技术网络应与其他所有网络隔离和分割。 5. 供应链必须安全:确保运营技术系统的供应链安全,防止恶意软件或硬件进入。 6. 人员是运营技术网络安全的关键:确保运营技术网络安全的人员具备必要的知识和技能。 文章还提供了如何使用这些原则来评估决策对运营技术网络安全的影响,以及如何实施这些原则的具体建议。
如何在OT环境中保护极其有价值的数据? 如何确保OT网络安全,防止恶意攻击? 如何提高OT系统的安全性和可靠性?
客服
商务合作
小程序
服务号
折叠