首页> 外文会议>International Conference on Information Society >High assurance cybersecurity plan templates for nuclear facilities: Two-dimensional layering of mutually orthogonal security controls for a high-assurance cybersecurity protection of critical computer-based systems in the post-Stuxnet era
【24h】

High assurance cybersecurity plan templates for nuclear facilities: Two-dimensional layering of mutually orthogonal security controls for a high-assurance cybersecurity protection of critical computer-based systems in the post-Stuxnet era

机译:核设施的高保证网络安全计划模板:相互正交的安全控制的二维分层,为后Stuxnet时代的关键计算机系统提供高保证的网络安全保护

获取原文

摘要

In the paper, an insight into two high assurance cybersecurity plan templates for nuclear facilities, namely the templates of the NRC RG 5.71:2010 and NEI 08-09 Rev.6:2010, is provided. The two cybersecurity plan templates were developed to assist nuclear industry to comply with legal requirements of Title 10 of the U.S. Code of Federal Regulation Section 73.54. The Regulation requires an adequate protection of digital computer and communication systems and networks in nuclear facilities. Regarding the compliance with the regulatory requirement, the paper discusses the concept of orthogonality in a two-dimensional layering of security controls as a way to more effectively deal with sophisticated, targeted and persistent threats of the post-Stuxnet era. Selected components of the Stuxnet attack scenario are used to illustrate that two dimensional layering of security controls makes each layer of the defense-in-depth protection more robust against both intentional and unintentional compromise. The paper also illustrates that due to recent changes in the cyber threat environment and advances in security protection, the cybersecurity plan templates of the NRC RG 5.71:2010 and NEI 08-09 Rev.6:2010 can be viewed as templates developed for incomplete initial threat conditions.
机译:本文提供了对两个核设施的高保证网络安全计划模板的见解,即NRC RG 5.71:2010和NEI 08-09 Rev.6:2010的模板。开发了两个网络安全计划模板,以帮助核工业遵守美国联邦法规第73.54条第10标题的法律要求。该条例要求对核设施中的数字计算机和通信系统及网络进行充分的保护。关于遵守法规要求,本文讨论了安全控制的二维分层中的正交性概念,以更有效地应对后Stuxnet时代的复杂,针对性和持久性威胁。 Stuxnet攻击场景的选定组件用于说明安全控制的二维分层结构,使纵深防御保护的每一层对于有意和无意的破坏都更加健壮。该文件还说明,由于网络威胁环境的最新变化和安全保护的进步,NRC RG 5.71:2010和NEI 08-09 Rev.6:2010的网络安全计划模板可以看作是为不完全的初始开发而设计的模板。威胁条件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号