Abstract:
To cope with information notification and feedback scenarios among multi-level departments in railway cybersecurity operation, this paper designed a railway cybersecurity operation information notification platform and sorted out the closed-loop management process for early warning information and emergency event notification. Based on the Software as a Service (SaaS) concept, the platform adopted multi-tenant design, directional data distribution, real-time message transmission and other technologies, and solved the problems of delayed information transmission and feedback, as well as insufficient standardization and normalization in daily operation. Practical application results show that the platform standardizes the formats and procedures of information notification, improves the timeliness of information notification and threat event disposal, enhances the efficiency of cybersecurity operation, and has promising application prospects.