首页> 外文会议>10th IET System Safety and Cyber-Security Conference 2015 >Safety and security — A story of interdependence
【24h】

Safety and security — A story of interdependence

机译:安全与保障—相互依存的故事

获取原文
获取原文并翻译 | 示例

摘要

Safety and security disciplines are often independent domains, with little interaction. There is increasing convergence driven by common technologies, platforms and networking, where safe operation of complex systems requires appropriate security. The two disciplines may also conflict, creating new hazardous that may require new safety functionality to reduce the security derived risk. Solely using the information assurance security attributes (confidentiality, integrity, and availability - CIA) is unsatisfactory when applied to the control systems and safety environments. This paper discusses emerging developments in the treatment of malicious acts in safety standards, and illustrates continuing challenges in vertical sectors, including medical. An adapted Parkerian Hexad assurance model is presented, which combines engineering good practice with information security, offering a more granular framework. The need to for a holistic approach to security is illustrated, with a recent cyber-attack, being one of the few causing physical destruction since Stuxnet in 2010. In this case the perpetrators traversed enterprise IT systems to compromise control and safety systems, causing significant damage.
机译:安全和保安学科通常是独立的领域,几乎没有交互。通用技术,平台和网络驱动着越来越多的融合,而复杂系统的安全运行需要适当的安全性。这两个准则也可能会冲突,从而产生新的危险,可能需要新的安全功能以减少安全性衍生的风险。当仅将信息保证安全属性(机密性,完整性和可用性-CIA)应用到控制系统和安全环境时,就不能令人满意。本文讨论了在安全标准中处理恶意行为的新兴发展,并说明了包括医疗在内的垂直领域的持续挑战。提出了一种经过修改的Parkerian Hexad保证模型,该模型将工程学的良好实践与信息安全相结合,从而提供了更精细的框架。说明了对整体安全性方法的需求,最近的网络攻击是自2010年Stuxnet以来为数不多的造成物理破坏的事件之一。在这种情况下,犯罪者越过企业IT系统来破坏控制和安全系统,从而造成重大破坏。损伤。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号