• 查询稿件
  • 获取最新论文
  • 知晓行业信息
司群, 田文, 陈彤. 建立铁路三位一体网络安全测评指标库研究[J]. 铁路计算机应用, 2020, 29(8): 38-42,47.
引用本文: 司群, 田文, 陈彤. 建立铁路三位一体网络安全测评指标库研究[J]. 铁路计算机应用, 2020, 29(8): 38-42,47.
SI Qun, TIAN Wen, CHEN Tong. Establishment of railway trinity network security evaluation index database[J]. Railway Computer Application, 2020, 29(8): 38-42,47.
Citation: SI Qun, TIAN Wen, CHEN Tong. Establishment of railway trinity network security evaluation index database[J]. Railway Computer Application, 2020, 29(8): 38-42,47.

建立铁路三位一体网络安全测评指标库研究

Establishment of railway trinity network security evaluation index database

  • 摘要: 通过对铁路典型的网络安全等级保护测评、风险评估测评和安全检查3类检测方法有机融合,研究建立铁路三位一体网络安全测评体系,重点解决如何高效测评问题。建立铁路网络安全测评指标库是解决上述问题的关键和基础步骤,指标库主要包括通用指标和专用指标,其中,通用指标按照网络安全等级保护2.0标准(简称:等级保护2.0)梳理出安全通用指标、云扩展指标、物联网扩展指标、移动互联网扩展指标和工业控制扩展指标;专用指标重点考虑业务安全,从完整性、保密性、可用性出发梳理铁路重要系统的测评指标。运输调度管理信息系统的专用指标、网络安全测评指标库作为现场开展测评工作的基本依据和参考,具有实际意义。

     

    Abstract: Through the organic integration of three typical railway detection methods, which were network security classified protection evaluation, risk assessment and security inspection, this article studied the establishment of railway trinity network security evaluation system, focusing on how to achieve efficient evaluation.The establishment of railway network security evaluation index database was the key and basic step to solve the above problems. The index library mainly included general indicators and special indicators. According to the network security level protection 2.0 standard, the general indicators were sorted out the general security indicators, cloud expansion indicators, Internet of Things expansion indicators, mobile Internet expansion indicators and industrial control expansion indicators.The special indicators were focused on business security and sorted out the evaluation index of important railway systems from the perspective of integrity, confidentiality and availability evaluation index.The special index and network security evaluation index database of transportation dispatching management information system are the basis of onsite evaluation, which has practical significance.

     

/

返回文章
返回