...
首页> 外文期刊>Journal of Telecommunications System & Management >Security Operations Center for OT environment – A framework
【24h】

Security Operations Center for OT environment – A framework

机译:OT环境安全运营中心 - 框架

获取原文
           

摘要

Operational technology or OT is a category of computing and communication systems to manage, monitor and control industrial operations with a focus on the physical devices (also known as Cyber Physical Devices) and processes being used by these Cyber Physical Devices (or Systems). OT often control essential services which affect people at large, such as water and power supply, oil & gas extraction to supply, mostly all large manufacturing units etc. Additionally, operational technology is also used to monitor these critical services to prevent hazardous conditions. Manipulation of these systems and processes could have extreme impacts on the end users of these services as well as workers within operational environments.Cyberattacks on critical infrastructure and strategic industrial assets are on the rise for some years now and is now believed to be among the top five global cyber risks. The cyberattacks have cost companies millions of dollars through the disruption of services and critical operations. To keep critical systems running and protect the financial results and reputation of any organization that includes industrial processes, it’s essential to improve industrial cyber security. However, securing OT environments, assessing them to determine remediation plans and strategies, and gaining visibility into them is challenging and requires different approaches than traditional IT environments.The IT environment is fairly protected and well-guarded by a Security Operations Center which keeps a constant vigil on the activities of the IT ecosystem under watch. The SOCs across the world have evolved and have reached a certain maturity in operations. However, for an OT environment, the SOC is still a new concept – primarily because the objectives of SOC of OT are different from those of IT. The mission and objectives of newer SOCs of today is about having an integrated security information and event management (SIEM) with a big data platform — complemented by workflow, automation and analytical tool. To create a SOC for OT would require re-engineering some of the OT processes, which because of being heavily dependent on the OT vendors result in a major task.Hence, there is a need to create a framework for OT SOC which helps organizations define a clear mission and objective statement for a fully operational OT SOC. The framework needs to define the roles (give directions) of the SOC team, the MSSP (if any), the OT vendors and the customer.
机译:操作技术或OT是一种计算和通信系统的类别,用于管理,监控和控制工业操作,其专注于物理设备(也称为网络物理设备)和这些网络物理设备(或系统)使用的过程。 OT经常控制影响人们的人的基本服务,例如水和电源,油气提取供应,主要是所有大型制造单位等。另外,运营技术还用于监测这些关键服务以防止有害危险条件。这些系统和流程的操纵可能对这些服务的最终用户来说可能极大影响,以及运营环境中的工人。关键基础设施和战略工业资产上的跨国数量持续了几年,现在被认为是顶部之一五个全球网络风险。 Cyber​​Actacks通过中断服务和关键业务的成本公司数百万美元。为了保持关键系统运行和保护任何包括工业流程的组织的财务结果和声誉,这对于改善工业网络安全至关重要。但是,确保他们的环境,评估他们以确定修复计划和策略,并获得对它们的可见性是具有挑战性的,并且需要不同的方法,而不是传统的IT环境。它环境相当受到保护,并由安全运营中心保持良好的保护,这保持不变守夜观察下IT生态系统的活动。世界各地的SOC已经发展起来,并在运营中达到了一定的成熟度。然而,对于OT环境,SoC仍然是一个新的概念 - 主要是因为OT的SOC的目标与它的目标不同。今天的新SoC的使命和目标是拥有一个具有大数据平台的综合安全信息和事件管理(SIEM) - 补充工作流,自动化和分析工具。要为OT创建SoC,需要重新设计一些OT进程,这是因为大量依赖于OT供应商导致主要任务产生了重大任务。因此,需要为OT SoC创建一个框架,这有助于组织定义一个完全运营的OT SOC的明确使命和客观声明。框架需要定义SoC团队的角色(给出方向),MSSP(IFSSP(IF),OT供应商和客户。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号