首页> 外文期刊>Advances in Science, Technology and Engineering Systems >Methodology for Management of Information Security in Industrial Control Systems: A Proof of Concept aligned with Enterprise Objectives.
【24h】

Methodology for Management of Information Security in Industrial Control Systems: A Proof of Concept aligned with Enterprise Objectives.

机译:工业控制系统中信息安全管理的方法:与企业目标一致的概念证明。

获取原文
       

摘要

This article is an extended version of the study presented at the IEEE Ecuador Technical Chapters Meeting (ETCM)-2016. At that time, a methodological proposal was designed, implemented, and applied in a group of industrial plants for the management of the information security of the Industrial control systems (ICS). The present study displays an adaptation and improvement of such methodology with the purpose of aligning the proposal for the effective management of information security with the strategic objectives. The development of this study has been divided into three distinctive phases. Firstly, we induced the articulation of PMI-PMBOK v5 and ITIL v3 both for the management of the project and for the verification of risks in the IT services. Second, we applied a set of risk mitigation strategies based on international standards as NIST 800-82 and 800-30. Thirdly, we assembled the two mentioned phases in a Guide for standards-based instructions and security policies, which previously have been encouraged on NIST 800-82, 800-53 and 800-12. Hereby, we observed the reduction of incidents of information security, the correct delimitation of the functions of the direct responsible of the ICS and the improvement of the communication between the operative and technical areas of the involved companies. The results demonstrate the functionality of these improvements, especially in the context of the availability and integrity of information, which generates an added value to the enterprise.
机译:本文是在IEEE厄瓜多尔技术章节会议(ETCM)-2016上提出的研究的扩展版本。当时,在一组工业工厂中设计,实施和应用了一种方法学建议,以管理工业控制系统(ICS)的信息安全。本研究显示了对这种方法的适应和改进,目的是使有效管理信息安全的建议与战略目标保持一致。这项研究的发展分为三个不同的阶段。首先,我们引入了PMI-PMBOK v5和ITIL v3的接口,以用于项目管理和IT服务中的风险验证。其次,我们根据国际标准(如NIST 800-82和800-30)应用了一系列风险缓解策略。第三,我们在基于标准的指令和安全策略指南中汇总了两个提到的阶段,以前在NIST 800-82、800-53和800-12中受到鼓励。因此,我们观察到减少了信息安全事件,正确划分了ICS的直接负责人的职能,并改善了所涉及公司的运营和技术领域之间的沟通。结果证明了这些改进的功能,特别是在信息的可用性和完整性的背景下,这为企业带来了附加值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号