论文部分内容阅读
根据《工业控制系统信息安全第1部分评估规范》(GB/T 30976.1-2014)的基本要求开展工业控制系统信息安全风险评估工作,能帮助我们进一步掌握被检查单位重要网络与信息系统基本情况,查找突出问题和薄弱环节,分析面临的安全威胁和风险,评估安全防护水平,提出针对性地防范对策和改进措施,促进安全防护能力和水平提升,预防和减少重大信息安全事件的发生,切实保障工业控制网络的信息安全,研究符合评估规范的风险评估方法并针对安全问题提出安全策略与建议。
According to the basic requirements of Part 1 of the Information Security for Industrial Control Systems (GB / T 30976.1-2014), the risk assessment of information security in industrial control systems can help us grasp the basic situation of the important network and information system under inspection, Find out the outstanding problems and weak links, analyze the security threats and risks faced, evaluate the level of security protection, put forward targeted prevention measures and improvement measures, promote the ability and level of security protection, prevent and reduce the occurrence of major information security incidents, and earnestly safeguard Industrial control network information security, research assessment methods in line with the risk assessment methods and safety issues for the proposed security strategy and recommendations.