当前位置:首页 > 报告详情

应对运营风险中的后果:为什么威胁和安全并不那么重要.pdf

上传人: 学*** 编号:187941 2024-12-26 16页 1.74MB

1、Addressing Consequence within Operational RiskWhy threats and security are just not that important2024 Aviation Cybersecurity Conference O.T.Gagnon III(Ollie),CISSP,CPP,PSPChief Homeland Security AdvisorIdaho National Laboratory Transportation-Aviation-Airport Dependency Profile(What is the most imp

2、ortant airport infrastructure?)Image source:INL.gov*Source:https:/www.cisa.gov/what-are-dependenciesElements of Risk Threat:A natural or manmade occurrence,individual,entity,or action that has or indicates the potential to harm.Vulnerability:A physical feature or operational attribute that renders a

3、n entity open to exploitation or susceptible.Consequence:The effect of an event,incident,or occurrence.Can your team list the top three critical systems,including their priorities,cyber and physical dependencies(internal/external),degree of IT/OT convergence,key stakeholders(internal/external),and t

4、he incident response and recovery plans?How well do you know your operational risks?Vulnerabilities Operational RiskThreatsConsequencesOperational RiskConsequences Captures“the uncertainties and hazards a company faces when it attempts to do its day-to-day activities.”Results from“breakdowns in inte

5、rnal procedures,people,and systems,”and focuses on“how things are accomplished within an organization.”Determined by analyzing the consequences,vulnerabilities,and threats within its procedures,workforce,and systems.ThreatsOperational RiskVulnerabilities Before an organization can consider vulnerabi

6、lities within and threats to its operations,it must first have a solid understanding of the consequences existing inside its infrastructure environment.Operational Risk(cont.)HumanCyberPhysicalConsiderations:Infrastructure vs.Critical Infrastructure Security vs.Resilience Dependency vs.Interdependen

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要讨论了操作风险中的后果管理,强调在威胁和安全性之外,对潜在后果的关注至关重要。文章指出,风险管理应侧重于分析程序、员工和系统中的后果、脆弱性和威胁。为提高安全性和韧性,文章提出了Critical Function Assurance (CFA)、Cyber-informed Engineering (CIE)和Consequence-driven Cyber-informed Engineering (CCE)等概念。CFA旨在识别、优先考虑和缓解依赖于数字技术的关键功能的固有风险;CIE原则则专注于将网络安全考虑融入物理系统的构思、设计、开发和运营中;而CCE是一个重复性的过程,旨在通过应用CFA和CIE的元素来确保关键功能的保障。文章还强调了在理解基础设施环境中的网络攻击和其对关键功能的影响方面,数字资产管理意识、供应链控制和计划韧性等方面的重要性。最后,文章提倡跨部门合作,将网络安全融入工程实践,确保国家的关键基础设施安全。
"如何识别关键基础设施的三大关键系统?" "如何在组织内部实现跨部门的运营风险管理?" "如何利用CFA、CIE和CCE框架提高关键功能的保障水平?"
客服
商务合作
小程序
服务号
折叠