【24h】

Security assessment methodology for industrial control system products

机译:工业控制系统产品的安全评估方法

获取原文

摘要

Industrial control systems (ICS) are at the heart of critical infrastructures and security is therefore important for such systems. In order to determine the security level of existing and planned systems, ICS products should be efficiently and comprehensively assessed. In this paper we present a methodology for assessing the security of a product or a system that can be used by security experts and non-experts alike. The methodology contains specific and concrete security recommendations (what), a rationale for each recommendation (why) as well as concrete implementation guidance (how). The methodology aims to help product teams to quickly and efficiently assess the security level of their products, prioritize resources on future development efforts, and generate security requirements for future products. We validate the approach by applying a concrete instantiation of the methodology to a fictitious ICS product.
机译:工业控制系统(ICS)是关键基础架构的核心,因此安全性对于此类系统至关重要。为了确定现有和计划中的系统的安全级别,应该对ICS产品进行有效而全面的评估。在本文中,我们提出了一种可以评估安全专家和非专家都可以使用的产品或系统安全性的方法。该方法包含具体和具体的安全建议(什么),每个建议的理由(为什么)以及具体的实施指南(如何)。该方法旨在帮助产品团队快速有效地评估其产品的安全级别,为未来的开发工作分配资源优先级,并为未来的产品生成安全要求。我们通过将方法的具体实例应用于虚拟ICS产品来验证该方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号