信息安全研究 ›› 2018, Vol. 4 ›› Issue (10): 959-964.

• 法律法规 • 上一篇    

我国工业控制系统信息安全政策和标准体系架构研究

安高峰,朱长明,雷晓锋,李亚楠   

  1. 北京天融信网络安全技术有限公司
  • 收稿日期:2018-10-11 出版日期:2018-10-15 发布日期:2018-10-11
  • 通讯作者: 安高峰
  • 作者简介:安高峰,男,1976年生,硕士,主要研究领域为工控信息安全标准、技术和政策 朱长明(通讯作者),男,1980年生,博士研究生,高级工程师,主要研究领域为工控安全、量子通信 雷晓锋,男,1979年生,硕士,标准总监,主要研究方向为网络安全技术、标准、政策、产业发展趋势等 李亚楠,女,1986年生,硕士研究生,工程师,主要研究领域为网络与信息安全、工控安全

Information Security Policy and Standard System of Industrial Control System in China

  • Received:2018-10-11 Online:2018-10-15 Published:2018-10-11

摘要: 中国制造2025、“互联网+”等战略的实施推进,使工控系统存在的信息安全问题日益突出.究其根源,工控安全相关标准不成体系、对实际工作的指导缺位是主要因素之一.在调研我国信息安全国家标准体系建设现状、整理国内工控安全相关标准的基础上,通过研究国际工控安全相关标准体系,结合国内工控安全需求的实际情况,梳理出了我国工业控制系统信息安全标准体系架构.该体系架构可作为企事业单位规划建设工控系统安全防护体系、制定工控系统安全管理规范、定期开展工控安全自检等活动提供参考及指导,切实提高企事业单位工控系统信息安全的保障能力.

关键词: 工业控制系统, 信息安全, 标准体系架构, 政策研究, 防护体系

Abstract: The implementation of China Manufacturing 2025 and the “Internet Plus” strategy has made the information security problems of industrial control system becoming increasingly prominent. Investigating its root causes, industrial security related standards are not systematic, and the lack of guidance for practical work is one of the main factors. On the basis of investigating the status quo of China's information security national standard system construction and sorting out domestic industrial security related policies and standards, this paper proposes the security related policies of China's industrial control system by studying the international industrial security related standards system and combining the actual situation of domestic industrial security requirements and standard systems. The system can provide reference and guidance for the industrial control system application enterprise to plan and construct its industrial control system security protection system, formulate the industrial control system security management norms, and regularly carry out the industrial control security self-inspection activities, and effectively improve the information security guarantee capability of the enterprise industrial control system.

Key words: industrial control system, information security, standard system, policy research, protection system