信息安全研究 ›› 2020, Vol. 6 ›› Issue (3): 272-278.

• 技术应用 • 上一篇    下一篇

工业控制系统安全等级保护测评研究

陈雪鸿,杨帅锋,孙岩   

  1. 国家工业信息安全发展研究中心保障技术所
  • 收稿日期:2020-03-02 出版日期:2020-03-10 发布日期:2020-03-02
  • 通讯作者: 陈雪鸿
  • 作者简介:陈雪鸿 硕士,副所长,高工.主要研究方向为电力信息系统安全、工业控制系统安全、等级保护、工业信息安全等. chenxuehong@cics-cert.org.cn 杨帅锋 硕士,工程师,主要研究方向为工业信息 安全、网络安全战略规划、数据安全、 关键信息基础设施安全等. yangsfsx@163.com 孙岩 博士,工程师,主要研究方向为工业信息 安全、边缘计算资源管理、博弈论等. cic2019sy@163.com

Research on the Safety Grade Protection Evaluation for Industrial Control Systems

  • Received:2020-03-02 Online:2020-03-10 Published:2020-03-02

摘要: 等级保护是国家网络安全的基本制度,工业控制系统密布于电力、油气、水利、铁路、烟草、钢铁、有色等多个行业,是等级保护中一类重要的保护对象.阐述了工业控制系统的概念、发展历程、分类和应用领域,介绍了依据不同标准在不同的角度下工业控制系统测评对象的选取标准、测评指标及测评过程,并给出了从如何测评过程指南中确定测评对象.针对实施工业控制系统等级保护测评中测评对象和测评指标选取的探讨,对开展工业控制系统测评具有典型的指导意义.

关键词: 工业控制系统, 等级保护, 信息安全测评技术, 测评对象, 测评指标

Abstract: Grade protection is the basic system of national cyber security. Industrial control system is widely used in many industries, such as power, oil and gas, water conservancy, railway, tobacco, iron and steel, nonferrous metal and so on. Industrial control system is an important kind of protection objects in grade protection. This paper explains the concept, development history, classification and application fields of industrial control systems, introduces the selection criteria, evaluation index and evaluation processes of industrial control system evaluation objects according to different standards and different angles, and gives how to determine the assessment targets from the guidelines of evaluation process. This paper introduces how to determine the evaluation object and index of industrial control system according to multiple grade protection standards step by step from complexity to simplicity, from whole to concrete, which has typical guiding significance for carrying out the evaluation of industrial control system.

Key words: industrial control system, grade protection, information security testing technology, evaluation object, evaluation index