【24h】

'A RISK-INFORMED CYBER-SECURITY PROGRAM APPROACH'

机译:“基于风险的网络安全计划方法”

获取原文

摘要

It is generally accepted that the effort required to comply with 10CFR73.54, "Protection of Digital Computer and Communication Systems and Networks" is much greater than initially anticipated. For example, instead of cyber security programs addressing handfuls of plant digital assets (CDAs), hundreds if not thousands of CDAs must be addressed. This situation is aggravated by the regulatory framework of 10CFR73.54 excluding risk management attributes of other cyber-security risk frameworks. Although this current situation has been improved by using a consequence-based methodology for CDA assessments, a more effective resolution will require fundamental changes to current regulatory requirements via rulemaking. Recognizing the Federal rulemaking process is lengthy, this paper outlines a near-term, risk-informed approach that improves cyber security program efficiency and increases program focus on public safety. This approach complies with WCFR73.54 and builds upon Industry's current CDA assessment methodology, facilitating incorporation into existing plant programs. With a December 2017 deadline for 10CFR73.54 compliance, incorporating a risk-informed approach into cyber security programs is realistically a post Milestone 8 program optimization initiative. Although this risk-informed approach is not a substitute for rulemaking, it does improve program performance in the near-term and is a meaningful step towards the long-term solution of rulemaking.
机译:公认的是,遵守10CFR73.54“数字计算机和通信系统及网络的保护”所需的工作量比最初预期的要大得多。例如,代替解决少数工厂数字资产(CDA)的网络安全计划,必须解决数百个(如果不是数千个)CDA。 10CFR73.54的监管框架加剧了这种情况,不包括其他网络安全风险框架的风险管理属性。尽管通过使用基于结果的方法进行CDA评估已改善了当前状况,但要想实现更有效的解决方案,就必须通过规则制定来对当前的监管要求进行根本性的改变。认识到联邦法规制定过程漫长,本文概述了一种短期的,具有风险意识的方法,可以提高网络安全计划的效率并增加对公共安全的计划关注度。该方法符合WCFR73.54,并以行业当前的CDA评估方法为基础,有助于将其纳入现有工厂计划中。遵循10CFR73.54标准的截止日期为2017年12月,将风险告知方法纳入网络安全计划实际上是里程碑8计划优化举措之后的目标。尽管这种基于风险的方法不能替代规则制定,但它确实可以在短期内提高计划绩效,并且是朝着长期解决规则制定迈出的有意义的一步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号