




版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進行舉報或認領(lǐng)
文檔簡介
PAGE|1
NationalCyber-InformedEngineeringStrategy
PAGE|2
NationalCyber-InformedEngineeringStrategy
NotefromtheSecretary
Intoday’sincreasinglyinterconnectedworld,America’ssafetyandwell-beingdependoncybersecurity.
That’swhyPresidentBidenconsidershardeningthenationagainstcyberattacksatoppriorityforhisadministration—andonethathasonlygrowninimportanceasthecountryembarksonthebiggestbuildoutofcriticalinfrastructureandmanufacturingcapacityinageneration.
Eachstageofthecleanenergytransformationthatwillbringwithitanopportunityandanimperativetofurtherincreasesecurity,reliability,andresilienceinAmerican’senergysector.TheCyber-InformedEngineering(CIE)Strategyshowsushowwecanseizetheopportunitytoaddressthesechallenges.
Thisframework,grownfromearlierCongressionaldirectionregardingthreatstothenation’senergysector,advocatesforanevolutionaryshiftacrosstheenergyindustryandrelatedinstitutions,includingresearchers,standardsbodies,Federalpartners,andothers.Itsrecommendationsreflectexpertiseandinsightfromenergycompanies,energysystemsandcybersecuritymanufacturers,standardsbodies,researchers,DOENationalLaboratories,andFederalpartnersinthecybersecurityandengineeringmissionspace.Itencouragestheadoptionofa“security-by-design”mindsetwithintheEnergySectorIndustrialBase,whichreferstobuildingcybersecurityintoourenergysystemsattheearliestpossiblestagesratherthantryingtosecurethesecriticalsystemsafterdeployment.ThankstoPresidentBiden’sBipartisanInfrastructureLaw,wecanmatchtheCIEframeworkwithnewinvestmentsincleanenergyinfrastructureandmanufacturingtobeginbuildingmoresecurecleanenergysystemshereathome.
CIEfurtherguidesourcyberworkforcedevelopmentbyhelpingusandourpartnersfocusonthestrategicintersectionbetweencybersecurityandengineering,addressinggapsinhowwetrainengineersandtechniciansandprovidingthemwiththemeanstobuildinsecurityfromthegroundup.Whenourworkforceisproperlyeducatedandsupported,wearebetterpositionedtomanufactureandmaintainthetoolsthathelpuspreventandquicklyrecoverfromcyberattacks.
Thisframeworkoffersusaclearpathforwardtothefutureofenergysecurity,inwhichAmericawillstandattheforefrontofglobalinnovationandcleanenergymanufacturing.FollowingtheCIEstrategywillhelpensurethatourgridisnotonlyresistanttoinitialattacks,butresilientenoughtopreventandmitigatedisruptionstoourenergysupplies,economy,andeverydaylives.
I’dliketooffermydeepgratitudeandappreciationfortheSecuringEnergyInfrastructureExecutiveTaskForce(SEIETF)whohelpedustakeacriticalstepforwardbyleadingthedevelopmentoftheCIEstrategy.Thework,however,continues.Itwilltakeclosecollaborationbetweengovernmentandindustrytoensureenergysystemsofthefuturearedesignedandbuiltforsecurityandreliability.Aswe
PAGE|3
NationalCyber-InformedEngineeringStrategy
pursueourtransitiontoacompletelycleanenergysector,wewillkeepsecurityandreliabilityfrontandcenter,andwillneedtostandshoulder-to-shoulderwithourinter-agencypartnersattheCybersecurityandInfrastructureSecurityAgency(CISA),NationalInstituteforStandardsandTechnology(NIST),andmoretoensurethisCIEstrategyisimplementedtoaddresscurrentandfuturethreatlandscapes.Together,wewillsecureourenergysectoranddeliverastronger,cleanerfuture.
JenniferGranholm
Secretary
U.S.DepartmentofEnergy
PAGE|4
NationalCyber-InformedEngineeringStrategy
NotefromtheDirector
TheU.S.energysectorfacesever-evolvingcybersecuritythreats.Accordingtothe2022OfficeoftheDirectorofNationalIntelligence(DNI)AnnualThreatAssessment1,ouradversariesmaintaincapabilitiestolaunchcyberattacksthatcoulddisruptcriticalinfrastructure,includingindustrialcontrolsystemsintheU.S.energysector.Cybersecurityattacksoncriticalinfrastructureareparticularlyconsequentialandensuringthesecurity,reliability,andresilienceofthesesystemsisatoppriorityfortheU.S.DepartmentofEnergy’s(DOE)OfficeofCybersecurity,EnergySecurity,andEmergencyResponse(CESER)anditspartnersingovernmentandtheprivatesector.
Thiswilltakeaconcerted,collaborativeeffortbetweengovernmentandindustrytoensureenergysystemsofthefuturearebuiltsecurelytoprovidereliableenergytothenation.Buildingenergysystemssecurelybydesignmeansensuringallphasesoftheenergysystemlifecycle–fromdesignanddevelopmenttoinstallationandoperation–aresecureandcanquicklyrecoverfromcyberattacks.Thenationnowhasanunprecedentedopportunitytoshapethecybersecurityofourmostcriticalinfrastructurefordecadestocome.
ThereleaseoftheCyber-InformedEngineering(CIE)supportsCESER’sfivepriorities.Thoseprioritiesinclude:1)Strengtheningthevisibilityofcyberthreatsinenergysystems;2)Addressingsupplychainrisks;3)Promotingsecurity-andresilience-by-design;4)BuildingcyberandresiliencecapacityintheprivatesectorandtheState,local,territorial,andtribalcommunities;and5)Beingpreparedtorespondinpartnershipwithourgovernmentandindustrypartnerswhenacyberincidentoccursintheenergysector.CIE,inmanyways,cutsacrossallthoseprioritiesthroughitsfivepillars:awareness,education,development,currentinfrastructure,andfutureinfrastructure.
CIEisanemergingframework,originatedbytheNationalLaboratoriesandadvancedbyDOE,tobuildcybersecurityintothenation’senergysystemsattheearliestpossiblestagesratherthantryingtosecurethesecriticalsystemsafterdeployment.CESERleadsDOE’seffortstoimplementCIEtoprotectcriticalenergyinfrastructureassetsandleveragesexpertiseofitsintra-agencypartners.Forexample,CESERworkscloselywithofficesacrosstheDepartmentsuchastheOfficeofEnergyEfficiencyandRenewableEnergy,theOfficeofElectricity,theOfficeofIntelligenceandCounterintelligence,andotherstoensurecybersecurityisbuiltintoenergysystemsoftodayandintothefuture.
Asapowersystemsengineer,Iknowhowcriticalitistoensurethatcybersecurityisbuiltintostandardsusedtodesignenergysystemsofthefuture.Tothatend,wewillneedpartnerswithstandardsbodiessuchastheInstituteofElectricalandElectronicsEngineers(IEEE)andtheInternationalElectrotechnical
1OfficeoftheDirectorofNationalIntelligence,AnnualThreatAssessmentoftheU.S.IntelligenceCommunity(April2022),4-24.
/files/ODNI/documents/assessments/ATA-2022-Unclassified-Report.pdf
.
PAGE|5
NationalCyber-InformedEngineeringStrategy
Commission,educatorsandresearchersinacademia,andmanyotherstohelpuschampiontheCIEprinciples.Weneedtoensurethatcybersecurityissynonymouswithreliabilityandsafetyinstandardsdevelopmentworkinggroupsandinthehallwaysofengineeringcollegestoensurewearesuccessful.Wecanaccomplishmuchmorewhenwetackletheseissuescollaboratively.
Further,whileDOEisleadingthiseffortfromanenergyindustryperspective,theoverallapproachwillrequireclosecollaborationandsignificantworkwithitsinter-agencypartnersattheCybersecurityandInfrastructureSecurityAgency(CISA),NationalInstituteforStandardsandTechnology(NIST),andotherstoensuretheCIErecommendationshereinareimplementedacrossthecountrytoaddressthecurrentandfuturethreatlandscapes.
IextendmythankstotheSecuringEnergyInfrastructureExecutiveTaskForceandIdahoNationalLaboratorywhowereinstrumentalinthedevelopmentofthestrategy.TherecommendationshereinreflecttheexpertiseofEnergySectorIndustrialBase(ESIB)stakeholderscomprisedofenergycompanies,manufacturers,standardsbodies,researchers,DOENationalLaboratories,andFederalpartnersinthecybersecurityandengineeringmissionspace.
PueshKumar
Director
OfficeofCybersecurity,EnergySecurity,andEmergencyResponse(CESER)
U.S.DepartmentofEnergy
PAGE|6
NationalCyber-InformedEngineeringStrategy
TABLEOFCONTENTS
NOTEFROMTHESECRETARY 2
NOTEFROMTHEDIRECTOR 4
EXECUTIVESUMMARY 7
CIEInPractice:ExamplesofEngineeringDecisionsInformedbyCyberRisks 9
INTRODUCTION 10
DefiningtheProblem 11
PrinciplesofCIE 12
KEYPREMISESOFTHENATIONALCIESTRATEGY 15
STRATEGICPILLARSANDRECOMMENDEDACTIONS 16
THECIESTRATEGYASAMODELFOROTHERCRITICALINFRASTRUCTURESECTORS 31
NEXTSTEPS 32
APPENDIXA:SECURINGENERGYINFRASTRUCTUREEXECUTIVETASKFORCEPARTICIPANTS 33
SeniorExecutiveGroup 33
SeniorTechnicalGroup 34
TechnicalProjectTeam:NationalCIEStrategy 35
APPENDIXB:EXAMPLESOFCIEIMPLEMENTATION 36
Consequence-drivenCyber-informedEngineering(CCE) 36
IntegratingCIEintoNuclearMicroreactorDesign 37
CybersecurityfortheOperationalTechnologyEnvironment(CyOTE?) 37
CIEinEducation 37
PAGE|7
NationalCyber-InformedEngineeringStrategy
Cyber-informedengineering(CIE)offersanopportunityto“engineerout”somecyberriskacrosstheentiredeviceorsystemlifecycle,startingfromtheearliestpossiblephaseofdesign—themostoptimaltimetointroducebothlowcostandeffectivecybersecurityapproaches.
CIEisanemergingmethodtointegratecybersecurityconsiderationsintotheconception,design,development,andoperationofanyphysicalsystemthathasdigitalconnectivity,monitoring,orcontrol.CIEapproachesusedesigndecisionsandengineeringcontrolstomitigateoreveneliminateavenuesforcyber-enabledattack,orreducetheconsequenceswhenanattackoccurs.
ExecutiveSummary
ThePersistentCybersecurityChallenge
Theindustrialcontrolsystemsthatoperatecriticalenergyinfrastructurefaceincreasinglysevereandsophisticatedcyberattacksfromdeterminedadversaries.Toavoiddisruptionstothenation’scriticalenergyfunctions,energysystemsmustbeengineeredtowithstandintentionalcybercompromise,exploitation,andmisuse.
Whiletraditionalengineeringincludesconsiderablesafetyandfailuremodeanalysis,theseriskmanagementapproachesrarelyaddresstherisksintroducedbyanintelligentandcapableadversarywiththegoalofdenying,disrupting,ordestroyingacriticalfunctionusingcybermeans.Mostcybersecuritysolutionsare“boltedon”lateintheengineeringlifecycle,ratherthanintrinsicallybuiltintothesystemdesign.
TheOpportunityofCyber-InformedEngineering
NationalCIEStrategyDirective
EnactedintolawonDecember20,2019,Section5726oftheNationalDefenseAuthorizationActforFiscalYear2020directedtheSecretaryofEnergytoestablishagovernment-industryworkinggrouptoaccomplishaseriesoftasks,includingtodevelopanationalcyber-informedengineeringstrategytoisolateanddefendenergyinfrastructurefromsecurityvulnerabilitiesandexploitsinthemostcriticalsystems.TheSecuringEnergyInfrastructureExecutiveTaskForcedevelopedthisNationalCIEStrategyforadoptionbytheDepartmentofEnergy.
Whilespecializedinformationtechnology(IT)andoperationaltechnology(OT)cybersecurityexpertsbringstrongcybersecuritycapabilitiestosecuringtoday’senergysystems,manyoftheengineersandtechnicianswhodesignandoperatetheseenergysystemscurrentlylacksufficientcybersecurityeducationandtrainingtoengineersystemsforcybersecurityfromtheoutset,inthesamewaytheyengineerthesesystemsforsafety.
ANationalCIEStrategyforEnergy
Pursuanttocongressionaldirection,2theU.S.DepartmentofEnergyandtheSecuringEnergyInfrastructureExecutiveTaskForcehavedevelopedastrategytoenabletheenergysectortoleadthenationinincorporatingCIEintothedesignandoperationofinfrastructuresystemsthatrelyondigitalmonitoringorcontrols.
2Section5726oftheNationalDefenseAuthorizationActforFiscalYear2020.
PAGE|8
NationalCyber-InformedEngineeringStrategy
TheNationalCIEStrategyisbuiltonfiveintegratedpillars(see
Figure1)
,offeringasetofrecommendationstoincorporateCIEasacommonpracticeacrosstheenergysector.Together,theseapproachesprovidethebodyofknowledge,thediverseandexpandedworkforce,andtheengineeringandmanufacturingcapacitytoapplyCIEtotoday’senergyinfrastructure,andtoengineerfutureenergysystemstoeliminateorreducetheabilityofacyber-enabledattacktosucceed.
Figure1.NationalCyber-InformedEngineeringStrategy
CIEprovidesthebasisandapproachforinstitutingacultureofcybersecuritywithintheenergyindustry,akintotheindustry’sstrongcultureofsafety.Leadingthisculturalshiftwillbetheengineers,industrialcontrolsystemtechnicians,cybersecurityprofessionals,manufacturers,andownersandoperatorsintheEnergySectorIndustrialBase.TheNationalCIEStrategypillarsprovideastrong,integratedfoundationtoacceleratethisculturalshift.ThenextstepinmovingCIEforwardwillbetoconveneabroadsetofstakeholderstodevelopdetailedimplementationplansforeachpillarofthestrategy.
WhilethisNationalCyber-InformedEngineeringStrategyhasbeendevelopedfortheenergysector,itcanserveasaleverageablemodelforothercriticalinfrastructuresectorstoadoptandincorporateCIEintoindustrypractices.CIEconceptsandstrategiesincludefoundationalengineeringprinciplesthatapplytoalltypesofengineeringforcriticalinfrastructure.EmbeddingCIEmethodsintotheeducationandcredentialingofthenation’snextgenerationofengineersandindustrialcontrolsystemtechnicianswillcreateacyber-awareworkforcethatcandesignandmanufactureresilientinfrastructuresystemsacrosssectors.
PAGE|9
NationalCyber-InformedEngineeringStrategy
CIEInPractice:ExamplesofEngineeringDecisionsInformedbyCyberRisks
CIEguidesanengineeringteamtoconsiderandmitigatethepotentialforcybercompromisethroughouttheengineeringdesignlifecycle,leveragingengineeringsolutionstolimitthepathwaysforcybersabotage,exploitation,theft,andmisusewithinthesystem.
InafullymatureCIEdesign,requirementswouldbedevelopedtodescribenotonlyexpectationsforhowthesystemwouldfunction,butalsospecifichigh-consequencecyberimpactswhichmustbepreventedwithinthesystemdesign.Duringthedesignprocess,theteamwouldmakeaffirmativedecisionsabouthowtobestaccomplishthoserequirements,whetherbyenactingmanualengineeringcontrols,limitingdigitalfunctionality,employingoperationalcybersecuritysolutions,orenactingmonitoringschemes,orcombinationsofalltheabove.Theriskofafuturecybercompromisewouldbetrackedanddiminishedasafundamentalengineeringrisk.
Whatdoesthismeanintoday’spractice?ThefollowinghypotheticalscenarioshighlightthetypesofdesignchangesandengineeringdecisionsthatcouldresultfromapplyingCIEduringthedesignandbuildprocess:
?A60-percentdesignreviewofagreenfieldwatertreatmentplantrevealsthatthedesignengineerreplacedthemanualhand-off-autoswitches—whichallowoperationsstafftoruntheplantmanually—withanetwork-basedcommunicationdevicewithoutmanualoverrides.Theteamelectstoundothismodification,justifyingthehighercostofconstructionwiththebenefitofassuredmanualcontrolsintheeventofacybercompromise.
?Adesignteamnotesthatthevibrationtripsensorforagasturbineisaddressableonthesameoperationaltechnologynetworkwiththeturbine,andthus,couldbecompromisedalongwiththeturbinebyanadversarywhogainsaccesstothenetwork.Becausethissensorisasafetyfeaturefortheturbine,theteamchoosestodeployitonanisolatednetwork—sothatitismoreinaccessibletocyberadversaries—andtoemployahigherlevelofsecuritycontrols,includingamonitoringsystem,toheightenawarenessofnetworkanomaliesaffectingthesensor.
?Acyberexerciserevealsthepotentialforadigitalcontrollertobeusedtosupplyaharmfulamountoftreatmentchemicalsintoaprocess,potentiallycausingdamagetoplantequipment.Theengineeringteamisunabletoremovethecontrollerfromserviceortoenactmanualoverrides,sotheychoosetoadoptanengineeringcontrollimitingthechemicalavailabletotheprocesstoanamountbelowtheharmfullevel.ThiscontrolisenactedthroughphysicalchangestothedispensingtankanddocumentedintheStandardOperatingProcedures.
?Duringthevalueengineeringprocessforawastewatertreatmentplantcontrolsystem,thedesignteamdecidedtosavemoneybyremovingredundanthardwiredcontrolsandreplacingthemwithdigitalinput/outputsfromtheindustrialcontroller.Duringareview,theengineeringteamnotedthatthisdecisionwouldremoveallmanualoperatingcapabilitiesfromthepumps,meaningasuccessfulransomwareattackonthecontrolsystemcouldleavethepumpsinoperable,resultinginpotentialspillsandequipmentdamage.Theprojectownerelectedtoabsorbtheadditionalcostinordertoensurethepotentialformanualcontrolsintheeventofacyberattack.
PAGE|10
NationalCyber-InformedEngineeringStrategy
Today,engineersandindustrialcontrolsystemtechniciansbuildenergysystemswithspecificgoalsforsafety,reliability,andfunctionality.Whilesystemsengineeringincludesconsiderablesafetyandfailuremodeanalysis,cybersecurityrisksareoftennotspecificallyaddressed—particularlytherisksofintentionalcybercompromise,exploitation,andmisuse.Simplyput,traditionalengineeringriskmanagementapproachesrarelyaddresstherisksintroducedbyanintelligentandcapableadversarywiththegoalofhigh-consequencecyber-enabledimpacts.4
Asaresult,mostcybersecuritysolutionsareintroducedlateintheengineeringlifecycle,ifatall,providinginadequateandmorecostlyprotectionforthenation’senergyindustrialcontrolsystems(ICS).This
Introduction
Currently,cybersecurityformostcriticalinfrastructurecontrolsystemsisaddressedseparatelyfromsystemdesignandengineering.Thisgaphasresultedinanever-growinglistofadditivesecuritytechnologiesthatareintroducedafterthefacttomitigatecybervulnerabilities.Addingsecuritytechnologiesafterthefactismorecostlyandlesseffective.Whatifcriticalenergyinfrastructuresystemsweredesignedandoperatedwithcybersecuritybuiltin,ratherthanboltedonafterdeployment?CIEprovidesawaytogreatlyreduce,andinsomecaseseliminate,cyberrisksfromtheoutsetandincreaseoverallefficiencyandeffectiveness.
CIEisanemergingapproachthataimstointegratecybersecurityconsiderationsintotheconception,design,build,andoperationofanyphysicalsystemthathasdigitalconnectivity,monitoring,orcontrol.3CIEcanbebroadlydefinedas:Theinclusionofcybersecurityconsiderationsasafoundationalelementofengineeringriskmanagementforanyfunctionaidedbydigitaltechnology.
CIELinkagetoZeroTrustandSecurebyDesign
Cyber-informedengineeringembraces“securebydesign”and“zerotrust”softwaresecuritystrategies,andexpandstheseconceptsbeyondsoftwareengineeringtotheengineeringofcyber-physicalsystems.
Secure-by-designsoftwaredevelopmentshiftsthesecurityfocusfromfindingandpatchingvulnerabilitiestoeliminatingdesignflawsinthearchitectureofasoftwaresystem.CIEexpandsthisconcepttobuildsecurearchitecturesintophysicalinfrastructuresystemsthathavedigitalaccessorcontrol.
Azero-trustarchitectureremovesanyimplicittrustfromdevicesoruseraccounts,movingawayfromtheconceptofasecurityperimeterthatkeepsattackersout.CIEembodiesthisapproachbyassumingthatcompromiseislikely,anddeployingresilientlayereddefensesthatminimizetheconsequencespossiblewhenanassetorcredentialiscompromised.
CIErepresentstheDepartmentofEnergy’sstrategyforimplementingtheseapproachesintoenergyinfrastructure.
approachmissessignificantopportunitiesto“engineerout”cyberrisk—thatis,usingearlydesigndecisionsandengineeringcontrolstomitigateoreveneliminateavenuesforcyber-enabledattack,orreducetheconsequenceswhenanattackoccurs.CIEembracesmanycomplementarysecurityapproachestoday,suchas“zerotrust”and“securebydesign,”conceptuallyextendingthembeyondapplicationtosoftwaresystemstoincludeapplicationtocyber-physicalinfrastructure.
CIEproposesashiftinfocusinthewaythenation’sengineers,controlsystemtechnicians,manufacturers,andoperatorsapproachsecurityinenergysystemsdesign.Researchersbegantodefine
3SeemoreinformationonCIEat
/cie
.
4High-consequenceimpacts,achievedusingcybermeans,thatmaydisruptenergysectorfunctionsthatarecriticaltothenation.
PAGE|11
NationalCyber-InformedEngineeringStrategy
Theadoptionofdigitaltechnologyintocriticaloperationalandengineeringfunctionscanintroducevulnerabilitiesthatcouldcompromisetheavailability,integrity,trustworthiness,orauthenticityofthecomplexcontrolsystemsservingthosefunctions.Unlesscybersecurityrisksareexplicitlyconsideredwithincurrentapproachestohazardevaluation,6thesevulnerabilitiesarenottypicallycaptured,missingcriticalopportunitiestoreduceoreliminatethemduringengineeringanddesign.Theengineerswhooversee,invent,design,create,install,maintain,anddisposeofthesecomplexcyber-physicalsystemsmaylackthenecessaryrequirements,context,7education,practices,andtools(inorderofdescendingimportance)toidentify,understand,andmitigatetheserisks.Instead,engineersandthetechnicianswhosupportthemtoooftenrelyontheexternalapplicationofcybersecuritymeasuresbyspecializedpractitionerslateinthesystemimplementationlifecycle.Thiscurrentstate
theCIEapproachin2017.5intheinterveningyears,thefederalgovernmenthassupportedseveraleffortsthatreducecyberriskstothenationbyapplyingCIEprinciplestocriticalenergyinfrastructureandnewsystemdesigns.However,thereisnotyetamatureengineeringdisciplineforidentifyingandaddressingcybersecurityriskearlyinintheconceptanddesignphases.TherearealsofewcommonlyappliedstandardsorguidelinestoperformsystemsengineeringriskmanagementforICScybersecurityrisksthroughoutthesystemslifecycle.
CIEremainsapromisingapproachthatisnotyetwidelyknown,understood,orimplemented.ThisNationalCIEStrategyoffersanintegratedsetofrecommendationstobringabouttheawareness,education,andresourcestointegrateCIEasacommonpracticewithintheEnergySectorIndustrialBase.
DefiningtheProblem
Engineers—andthetechnicianswhosupporttheengineeringprocess—arecriticaltothedesign,implementation,andsecureoperationofcomplexenergyinfrastructureandcontrolsystems.Eveninthiscriticalrole,engineersoftenlacktraining,abodyofknowledge,andotherreinforcementofcybersecuritypracticestoeffectivelyaddresscyberthreatsinenergyinfrastructure.Giventhecurrentandincreasingcriticalityofdigitalcontrolsystemswithincriticalenergyinfrastructure,thisisaprioritygapthatmustbeaddressedbytheengineeringcommunityandthenation.
CurrentState
AlignmentofCIEwithIndustryStandardsandGuidelines
TheNationalCIEStrategywillinformtheevolutionandmaturationofindustrystandardsandguidelinestoalignwithCIEprinciplesandprovidemanufacturersandassetownerswithessentialtoolstodemonstratetheiradoptionofCIE.RecentguidanceshowsstrongalignmentwithCIE.AlignmentwithCIEcanbeanearlytargetforthestandardsspecificationactivitiesrecommendedintheDevelopmentpillar.ExamplesincludetheInternationalSocietyofAutomation(ISA)/InternationalElectrotechnicalCommission(IEC)62443seriesofstandards,theNationalInstituteofStandardsandTechnology(NIST)SP800-160guideline,andtheSAEInternationalG-32Cyber-PhysicalSystemsSecurityCommitteestandardswork.
5RobertS.Anderson,JacobBenjamin,VirginiaL.Wright,LuisQuinones,andJonathanPaz,Cyber-InformedEngineering,IdahoNationalLaboratory,2017.
doi:10.2172/1369373
.
6Suchas:failuremodeseffectsanalysis(FMEA),What-Ifanalysis,hazardandoperabilitystudy(HAZOP),faulttreeanalysis(FTA),andeventtreeanalysis(ETA).
7Contextreferstothebroaderenvironmentinwhich
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責。
- 6. 下載文件中如有侵權(quán)或不適當內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 有機化學 有機上期末試卷(含答案)學習資料
- 2025風力發(fā)電項目合同
- 山東省東營市利津縣2024-2025學年下學期期中考試七年級道德與法治試題及答案 山東省東營市利津縣2024-2025學年下學期期中考試七年級道德與法治試題
- 2025糧食收購銷售合同協(xié)議書范本
- 2025辦公室改造工程(承包)合同承包電路改造合同
- 2025綜合裝修合同范本
- 2025勞動合同集錦范文
- 2025烘焙技術(shù)合作協(xié)議合同
- 2025BT項目合同范本
- 2025年企業(yè)合同模板集錦
- 2025建筑信息模型技術(shù)員(中級)技能鑒定精練考試指導題庫及答案(濃縮300題)
- 2025年紅十字初級急救員證考試題庫及答案(一)
- 腎梗死護理措施
- 《頸椎病的針灸治療》課件
- 湖水水質(zhì)監(jiān)測方案
- 醫(yī)美診所院感知識培訓課件
- 河北省氣象部門招聘筆試沖刺題2025
- 塔吊司機崗位責任制樣本(2篇)
- 監(jiān)理工程師歷年考試真題及答案下載
- 糖尿病患者飲食指導課件
- 施工項目安全教育培訓制度(2篇)
評論
0/150
提交評論