首页> 外文会议>Safety-critical systems symposium >Waking up to The Insider as a Safety-Critical Threat
【24h】

Waking up to The Insider as a Safety-Critical Threat

机译:作为安全关键威胁唤醒了内部人士

获取原文

摘要

The Insider threat is rarely considered as part of functional safety to inform design, process and procedure. Worryingly, it is often neglected as part of safety and risk management practices entirely. This must change in light of high profile cases in recent years where Insiders have been seen to pose a severe threat. Industry must attempt to analyse and understand Insider threat risk and build this into integral processes, which will require close collaboration across diverse technical areas and specialisms. Government policy may even be developed in the coming years, similar to that of US Executive Order 13587, which necessitates a more comprehensive consideration of these risks. Now is the time for safety-critical industries to wake up to the Insider threat as one of the most real and present dangers to organisations in the modern age. This paper is a thought-piece about how Insider threat could be dealt with as part of normal engineering practice, and proposes a concept methodology for the formal assessment of Insider threat risk to systems and organisations. The paper deals only with deliberate and malicious acts (intended to do harm in some way), rather than the unintentional insider threat.
机译:内幕威胁很少被认为是通知设计,过程和程序的功能安全的一部分。令人担忧的是,它通常被忽视,作为完全安全和风险管理实践的一部分。近年来,这必须在高调案例中改变近年来,其中有人看到了造成严重威胁。行业必须试图分析和理解内幕威胁风险,并将其建立在一个组成的过程中,这将需要在各种技术领域和专业方面密切合作。政府政策甚至可能在未来几年内制定,类似于美国执行令13587,这需要更全面地考虑这些风险。现在是安全关键产业的时候唤醒内部人士威胁,作为现代时代的最真实和现在的危险之一。本文是一个关于在正常工程实践中如何处理的内幕威胁的思想家,提出了一个概念方法,用于对系统和组织进行正式评估内幕威胁风险的概念方法。本文只有刻意和恶意行为(旨在以某种方式造成伤害),而不是无意的内幕威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号