首页> 外文会议>Safety-critical systems symposium >Waking up to The Insider as a Safety-Critical Threat
【24h】

Waking up to The Insider as a Safety-Critical Threat

机译:唤醒内幕人士作为安全关键威胁

获取原文
获取外文期刊封面目录资料

摘要

The Insider threat is rarely considered as part of functional safety to inform design, process and procedure. Worryingly, it is often neglected as part of safety and risk management practices entirely. This must change in light of high profile cases in recent years where Insiders have been seen to pose a severe threat. Industry must attempt to analyse and understand Insider threat risk and build this into integral processes, which will require close collaboration across diverse technical areas and specialisms. Government policy may even be developed in the coming years, similar to that of US Executive Order 13587, which necessitates a more comprehensive consideration of these risks. Now is the time for safety-critical industries to wake up to the Insider threat as one of the most real and present dangers to organisations in the modern age. This paper is a thought-piece about how Insider threat could be dealt with as part of normal engineering practice, and proposes a concept methodology for the formal assessment of Insider threat risk to systems and organisations. The paper deals only with deliberate and malicious acts (intended to do harm in some way), rather than the unintentional insider threat.
机译:内部人员威胁很少被视为功能安全的一部分,以告知设计,过程和程序。令人担忧的是,它经常被完全忽略为安全和风险管理实践的一部分。鉴于近年来内部人员被视为构成严重威胁的引人注目的案件,这必须改变。行业必须尝试分析和理解内部威胁的风险,并将其构建到完整的流程中,这将需要跨不同技术领域和专业领域的紧密合作。未来几年甚至可能会制定政府政策,类似于美国第13587号行政命令,该命令需要更全面地考虑这些风险。现在是安全至关重要的行业意识到内部人员威胁的时候了,这是现代组织面临的最现实和当前的威胁之一。本文是关于如何作为常规工程实践的一部分处理内部威胁的思想,并提出了一种概念方法,用于对系统和组织的内部威胁风险进行正式评估。本文仅涉及故意和恶意行为(旨在以某种方式造成伤害),而不涉及无意的内部威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号