Journal of Information Security Research ›› 2016, Vol. 2 ›› Issue (9): 827-833.

Previous Articles     Next Articles

Research on the Framework of Smart City Cyber Security

  

  • Received:2016-09-19 Online:2016-09-15 Published:2016-09-19

智慧城市网络安全体系框架研究

吕欣   

  1. 国家信息中心
  • 通讯作者: 吕欣
  • 作者简介:博士,国家信息中心副研究员,国家信息中心时空大数据研究中心秘书长,主要研究方向为网络安全评价体系、网络安全战略、网络空间安全体系结构. lux@cei.gov.cn

Abstract: In order to ensure the healthy and orderly development of smart city, the government issued the Guidance on Promoting the Healthy Development of Smart City. The guidance clearly puts forward the need to ensure longterm security of smart city network, establish urban cyber security guarantee system and management system, achieve security controllability of basic network and key information system, guarantee the security of important information resources, and effectively protect the information of residents, enterprises and government. This paper analyzes the characteristics and cyber security demands of smart city. Based on system engineering method, this paper adopts model abstract and AHP method to put forward the smart city cyber security reference framework. According to the functions of assurance, smart city cyber security assurance system can be divided into smart city cyber security strategic assurance subsystem, smart city cyber security organizational assurance subsystem, smart city cyber security technical assurance subsystem, smart city cyber security management procedural subsystem, and smart city cyber security operational assurance subsystem. By building a complete and systemic smart city cyber security assurance system, a manageable, controllable and credible smart city network can be realized. The assurance system will boost the healthy development of smart city. In addition, this paper also studies the process model of smart city cyber security assurance, which will provide technical reference for the establishment of sustainable smart city cyber security assurance capability.

Key words: smart city, cyber security demand, cyber security assurance, cyber security management

摘要: 为确保智慧城市建设健康有序推进,国家发布《关于促进智慧城市健康发展的指导意见》,指导意见中明确提出要确保智慧城市网络安全长效化,建立城市网络安全保障体系和管理制度,实现基础网络和要害信息系统安全可控,切实保障重要信息资源安全,确保居民、企业和政府的信息得到有效保护.研究分析了智慧城市特征及网络安全需求,基于系统工程研究方法,采用模型抽象法和层次划分法,提出智慧城市网络安全参考框架.按照保障的功能,将智慧城市网络安全保障体系分为智慧城市网络安全战略保障、智慧城市网络安全管理组织保障、智慧城市网络安全技术保障、智慧城市网络安全管理过程保障与智慧城市网络安全运行保障.通过构建智慧城市安全保障体系,实现智慧城市网络安全的可管、可控、可信,助力智慧城市的健康发展.此外,还研究了智慧城市网络安全保障的过程模型,为建立可持续提升的智慧城市网络安全保障能力提供技术参考.

关键词: 智慧城市, 网络安全需求, 网络安全保障, 网络安全管理