首页> 外文OA文献 >Control Consistency as a Management Tool: The Identification of Systematic Security Control Weaknesses in Air Traffic Management
【2h】

Control Consistency as a Management Tool: The Identification of Systematic Security Control Weaknesses in Air Traffic Management

机译:控制一致性作为管理工具:空中交通管理中系统安全控制弱点的识别

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In 2008 EUROCONTROL published Information and Communications Technology (ICT) Security Guidance to Air Navigation Service Providers (ANSPs), to assist them in complying with regulatory security requirements. This included a visualisation tool which allowed the consistency of control sets to be reviewed and communicated: consistency being the degree to which more sophisticated controls were supported by core controls. The validation of that guidance included surveys which were conducted to contrast current practice in European ANSPs with a baseline control set based on ISO/IEC 27001:2005. The consistency test revealed significant gaps in the control strategies of these organisations: despite relatively sophisticated control regimes there were areas which lacked core controls. Key missing elements identified in the ANSPs surveyed include security management and senior management engagement, system accreditation, the validation and authentication of data used by ATM systems, incident management, and business continuity preparedness. Since anonymity requires that little can be said about the original surveys these results are necessarily indicative, so the paper contrasts these findings with contemporaneous literature, including audit reports on security in US ATM systems. The two sources prove to be in close agreement, confirming the value of the control consistency view in providing an overview of an organisation's security control regime.
机译:在2008年,EUROCONTROL发布了《针对空中航行服务提供商的信息和通信技术(ICT)安全指南》,以帮助他们遵守法规安全要求。这包括一个可视化工具,该工具可以检查和传达控件集的一致性:一致性是核心控件支持更复杂控件的程度。对该指南的验证包括进行调查,以对比欧洲ANSP中基于ISO / IEC 27001:2005的基线控制集的当前实践。一致性测试表明,这些组织的控制策略存在重大差距:尽管控制机制相对复杂,但仍有一些区域缺乏核心控制。被调查的ANSP中发现的关键缺失要素包括安全管理和高层管理人员参与,系统认证,ATM系统使用的数据的确认和认证,事件管理以及业务连续性准备。由于匿名要求几乎不能说原始调查,所以这些结果必然是指示性的,因此本文将这些发现与同期文献进行了对比,包括有关美国ATM系统安全性的审计报告。事实证明这两个来源非常吻合,从而在提供组织的安全控制机制概述时确认了控制一致性视图的价值。

著录项

  • 作者

    Chivers Howard Robert;

  • 作者单位
  • 年度 2016
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号