首页> 外文会议>SpaceOps conference >A Standardized Approach for Providing Information Security to Space Projects
【24h】

A Standardized Approach for Providing Information Security to Space Projects

机译:为太空项目提供信息安全的标准化方法

获取原文
获取外文期刊封面目录资料

摘要

Over the last years, information security became more and more important for space operations. Widely available connectivity provided by modern communication technology not only resulted in an increasing threat for attacks on the infrastructure but also offered possibilities like teleworking leading to new challenges in respect to system security. A variety of space projects is being operated from our multi-mission control center (GSOC), each having its own requirements regarding information security. As cost-reduction is also a key factor for space operations these days, there is a need for being able to provide information security to all of these projects in an organized and standardized way so that synergies can be used wherever possible - both in the implementation and in the operational phases of the mission. Nevertheless both the methods and processes used as well as the implemented controls must not be too rigid in order to be able to respond to mission-specific requirements resulting e.g. from different classification levels or special needs of a customer. In order to realize the aspects mentioned above, we chose the ISO/IEC 27001 standard as the baseline, guaranteeing - in contrast to national standards - international publicity and acceptance. This standard allows management of information security on a risk oriented basis. Furthermore this approach offers the opportunity to obtain a certification. In this paper we will describe how the information security management system at GSOC (ISMS) was designed and how general information security guidelines covering important aspects like secure operations, user management, secure network and much more have been developed based on ISO 27001, taking into account important processes for space operations. Using the example of the EDRS mission, we show how these general guidelines can be used to set up security concepts for upcoming space missions while taking benefit from already implemented systems. In addition to that, we explain how project-specific processes collude with the general guidelines and how special requirements can be incorporated. We will show the procedures which were evolved for managing the complete ISMS and for identifying gaps quickly, giving the opportunity to space projects to take corrective measures in order to be compliant with the security policies. Due to its flexibility, the ISMS also showed to be able to bear with the changes caused by the update of the ISO 27001 in 2013.
机译:在过去的几年中,信息安全对于太空作战变得越来越重要。现代通信技术提供的广泛可用的连通性不仅导致对基础架构攻击的威胁越来越大,而且还提供了诸如远程办公之类的可能性,从而给系统安全性带来了新的挑战。我们的多任务控制中心(GSOC)正在运行各种太空项目,每个项目都有自己的信息安全要求。由于降低成本也是当今太空作战的关键因素,因此需要能够以有组织和标准化的方式为所有这些项目提供信息安全,以便在实施过程中尽可能利用协同作用。在任务的运作阶段。然而,所使用的方法和过程以及所实施的控制都不能太死板,以便能够响应特定任务的要求,例如:来自不同的分类级别或客户的特殊需求。为了实现上述方面,我们选择了ISO / IEC 27001标准作为基准,与国家标准相反,我们保证了国际宣传和接受。该标准允许在面向风险的基础上管理信息安全。此外,这种方法还提供了获得认证的机会。在本文中,我们将描述如何设计GSOC(ISMS)的信息安全管理系统,以及如何基于ISO 27001制定涵盖诸如安全操作,用户管理,安全网络等重要方面的通用信息安全指南,说明了太空作战的重要过程。以EDRS任务为例,我们展示了如何利用这些通用准则为即将到来的太空任务建立安全概念,同时又能从已经实施的系统中受益。除此之外,我们还将说明特定于项目的流程如何与通用准则相结合,以及如何纳入特殊要求。我们将展示为管理完整的ISMS和快速识别差距而开发的程序,从而使太空项目有机会采取纠正措施,以符合安全策略。由于其灵活性,ISMS还显示出能够承受2013年ISO 27001更新所引起的变化。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号