【24h】

Security Blind Spots in the ATM Safety Culture

机译:ATM安全文化中的安全盲区

获取原文

摘要

In 2008 EUROCONTROL published Information and Communications Technology (ICT) Security Guidance to Air Navigation Service Providers (ANSPs), to assist them in complying with regulatory security requirements. The validation of that guidance included surveys which were conducted to contrast current practice in European ANSPs with a baseline control set based on ISO/IEC 27001:2005. The surveys are confidential and unpublished, however, by identifying the controls that are missing in all the survey responses it is possible to identify potential 'blind spots' in Air Traffic Management (ATM) security while maintaining the anonymity of the respondents. Key issues identified in this way include security management and senior management engagement, system accreditation, the validation and authentication of data used by ATM systems, incident management, and business continuity preparedness. Since little can be said about the original surveys these results are necessarily indicative, so the paper contrasts these findings with contemporaneous audit reports on security in US ATM systems. The two sources prove to be in close agreement, suggesting that the issues identified are systematic difficulties in introducing security into Air Traffic Management culture.
机译:在2008年,EUROCONTROL发布了《空中航行服务提供商的信息和通信技术(ICT)安全指南》,以帮助他们遵守法规安全要求。该指南的有效性包括调查,该调查旨在对比欧洲ANSP中基于ISO / IEC 27001:2005的基准控制集的当前实践。这些调查是机密的且未公开,但是,通过确定所有调查答复中都缺少的控制措施,可以在保持受访者匿名的同时,识别出空中交通管理(ATM)安全中的潜在“盲点”。以这种方式确定的关键问题包括安全管理和高级管理人员参与,系统认证,ATM系统使用的数据的验证和认证,事件管理以及业务连续性准备。由于对原始调查几乎不能说这些结果必然是指示性的,因此本文将这些发现与有关美国ATM系统安全性的同期审计报告进行了对比。这两个消息来源被证明是非常一致的,表明所发现的问题是将安全性引入空中交通管理文化的系统性困难。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号