摘要
信息技术在工业控制系统中的广泛运用,逐步打破了工业控制网络环境的封闭性,暴露了系统的脆弱性。国内外层出不穷的工控安全事件,给国家安全敲响了警钟,我国工业基础设施安全面临严峻挑战。基于上述背景,分析了我国大型工业企业,尤其是流程工业企业的工业控制系统运维现状。围绕人、财务、信息、技术四种资源,建立了工业控制系统安全运维模型,提出了安全运维本质对象是业务,阐述了数据、载体、环境和边界四种安全运维实体对象的内涵及其关联关系。基于ISO 27001信息安全管理体系,提出了工业控制系统“安全运维”和“运维安全”两种模式,并从服务对象和服务目标角度分析了两种模式的区别和共性。
The extensive use of information technology in industrial control systems has gradually broken the closedness of the industrial control network environment and exposed the vulnerability of the system.The endless stream of industrial-controlled security incidents at home and abroad has sounded the alarm for national security,and China's industrial infrastructure security faces severe challenges.Based on the above background,the operation and maintenance status of industrial control systems of large industrial enterprises are analyzed,especially process industrial enterprises in China.Based on the four resources of people,finance,information and technology,this paper establishes a safe operation and maintenance model of industrial control system and proposes safe transportation.The dimension of the essence object is the business,expounding the connotation and relationship of the four security operations entity objects of data,carrier,environment and boundary.Based on the ISO 27001 information security management system,two modes and processes of“safe operation and maintenance”and“operation and maintenance security”of industrial control system are proposed,and the differences and commonalities between the two modes are analyzed from the perspective of service objects and service targets.
作者
陈政熙
张家鹏
CHEN Zhengxi;ZHANG Jiapeng(Shanghai Institute of Process Automation & Instrumentation Co. ,Ltd. ,Shanghai 200233,China)
出处
《自动化仪表》
CAS
2020年第5期98-102,106,共6页
Process Automation Instrumentation
基金
上海市2018年度“科技创新行动计划”高新技术领域项目(18511106000)
2018年工信部工业互联网创新发展工程典型行业工业互联网企业级集中化安全监测平台建设基金资助项目。
关键词
工业控制系统
运维模式
安全运维
运维安全
信息安全
工控安全
Industrial control system
Operation and maintenance mode
Safe operation and maintenance
Operation and maintenance security
Information security
Industrial control security