透過您的圖書館登入
IP:3.146.221.204
  • 期刊

資訊與工控資通安全風險管理機制評估

Evaluation of Information and Industry Security Risk Management Methodology

摘要


在物聯網及工業4.0的趨勢下,將IT與OT兩大領域進行結合,然而這也使得資訊安全的事件頻傳,這些事件讓資訊安全不得不成為OT必面對的問題。本研究透過比較OT領域工業系統安全風險管理標準IEC 62443-3-2、IT領域資訊安全ISO/IEC 27005、Risk IT Framework以及NIST SP800-39評估整合型資通安全風險管理方法應關注的重點,針對OT與IT標準中的風險管理流程、關注的粒度、分級方式、風險控制措施及各標準所針對目標分析其異同,提出ISO/IEC 27005對應至IEC 62443-3-2的應用,提供組織OT與IT結合的概念,以降低組織在工業領域的資訊與網路安全風險,減少企業組織因資安事件所帶來的龐大損失,提升資訊安全防護的品質,確保組織資訊與網路的安全,進而使組織能永續經營。

並列摘要


Under the trend of Internet of Things and Industry 4.0, two major fields, IT and OT, are integrated. However, this has also led to frequent information security incidents, and these incidents have made information security an issue that OT must face. This research compares the risk management standard IEC 62443-3-2 for industrial system security in OT domain, ISO/IEC 27005 for information security in IT domain, Risk IT Framework and NIST SP800- 39 to evaluate the key concerns of integrated information security risk management approach, and focuses on the risk management process, granularity of concerns, and classification methods in OT and IT standards. We propose the application of ISO/IEC 27005 to IEC 62443-3-2 to provide organizations with the concept of integrating OT and IT to reduce information and network security risks in industrial areas, reduce the huge losses caused by information security incidents, and improve information security. It also improves the quality of information security protection and ensures the security of organization information and network, thus enabling organizations to operate sustainably.

參考文獻


Anderson, D., COSO ERM: Getting risk management right: Strategy and organizational performance are the heart of the updated framework, in Internal Auditor. 2017. p. 38.
IEC, IEC/TR 62443-3-1 Security Technologies for Industrial Automation and Control Systems. 2009, Internation Electrotechnical Commission.
IEC, IEC 62443 Security for Industrial Automation and Control Systems. 2009-2018, Internation Electrotechnical Commission.
IEC, IEC 62443-2-1 Industrial communication networks-Network and system security: Establishing an industrial automation and control system security program. 2010, Internation Electrotechnical Commission.
IEC, IEC 62443-2-2 Security for industrial automation and control systems: IACS protection levels. 2018, International Electrotechnical Commission.

延伸閱讀