首页> 外文会议>DISTRIBUTech - Conference and Exhibition >Compliance Conundrum: To Comply or To Prove Compliance?
【24h】

Compliance Conundrum: To Comply or To Prove Compliance?

机译:合规概念:遵守或证明合规性?

获取原文

摘要

There are two important aspects to compliance with the NERC CIP 002-009 CyberSecurity standards. The first aspect of NERC CIP compliance involves deploying hardware and software solutions or processes to accomplish cyber security goals. This could involve deploying firewalls, intrusion detection systems, video surveillance systems, or authentication software. The second aspect of NERC CIP compliance involves managing data that substantiates and documents an organization's compliance efforts. NERC CIP has very challenging requirements which not only require detailed documentation on deployed solutions (e.g. firewalls, etc), but documentation on how those solutions were tested, documentation on back-up plans if the solution fails, and documentation on testing the back-up solution. It is natural to focus on the deployment of hardware and software or enacting processes and practices to adhere to compliance requirements. Just as important, but often overlooked, is establishing a framework for proving one's compliance to both internal and external audiences. NERC CIP makes it hard to overlook compliance proof because of its strong theme of compliance accountability.
机译:遵守NERC CIP 002-009网络安全标准有两个重要方面。 NERC CIP合规性的第一方面涉及部署硬件和软件解决方案或流程来完成网络安全目标。这可能涉及部署防火墙,入侵检测系统,视频监控系统或身份验证软件。 NERC CIP遵从性的第二个方面涉及管理实质性和记录组织合规努力的数据。 NERC CIP具有非常具有挑战性的要求,这些要求不仅需要有关部署的解决方案(例如防火墙等)的详细文档,而且还需要如何测试这些解决方案的文档,如果解决方案失败,则在备份计划中记录备份计划,以及测试备份的文档解决方案。它很自然地关注部署硬件和软件或制定流程和实践,以遵守合规性要求。同样重要,但经常被忽视,正在建立一个框架,以证明一个人对内部和外部受众的遵守情况。 NERC CIP由于其强大的合规责任主题而难以忽视合规性证明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号