Control Systems Cyber Security: Defense in Depth Strategies
暫譯: 控制系統網路安全:深度防禦策略

Department of Homeland Security

相關主題

商品描述

Information infrastructures across many public and private domains share several common attributes regarding IT deployments and data communications. This is particularly true in the control systems domain. A majority of the systems use robust architectures to enhance business and reduce costs by increasing the integration of external, business, and control system networks. However, multi-network integration strategies often lead to vulnerabilities that greatly reduce the security of an organization, and can expose mission-critical control systems to cyber threats. This document provides guidance and direction for developing ‘defense-in-depth’ strategies for organizations that use control system networks while maintaining a multi-tier information architecture that requires: •Maintenance of various field devices, telemetry collection, and/or industrial-level process systems •Access to facilities via remote data link or modem •Public facing services for customer or corporate operations •A robust business environment that requires connections among the control system domain, the external Internet, and other peer organizations.

商品描述(中文翻譯)

許多公共和私人領域的信息基礎設施在IT部署和數據通信方面共享幾個共同特徵。這在控制系統領域尤其明顯。大多數系統使用穩健的架構來增強業務並降低成本,通過提高外部、業務和控制系統網絡的整合。然而,多網絡整合策略往往會導致漏洞,這大大降低了組織的安全性,並可能使關鍵任務的控制系統面臨網絡威脅。本文件提供了針對使用控制系統網絡的組織開發「深度防禦」策略的指導和方向,同時維持一個多層次的信息架構,該架構要求:•維護各種現場設備、遙測收集和/或工業級過程系統 •通過遠程數據鏈路或調製解調器訪問設施 •面向公眾的服務以支持客戶或企業運營 •一個穩健的商業環境,要求控制系統領域、外部互聯網和其他同行組織之間的連接。