首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 SAE EPR2021020
到馆提醒
收藏跟踪
购买正版
Unsettled Topics Concerning Airport Cybersecurity Standards and Regulation 关于机场网络安全标准和监管的未解决话题
发布日期: 2021-09-13
大型国际机场是整个航空业的缩影,容纳了数百种不同类型的航空和非航空利益相关者:飞机、乘客、航空公司、旅行社、空中交通管理和控制、零售商店、跑道系统、建筑管理、地面运输等。它们相关的信息技术和网络物理系统,以及成倍增加的互联数量,构成了巨大的网络安全挑战。与过去几十年里一直受到认真对待的物理安全挑战不同,网络安全挑战- 对机场的攻击不断发生,但大多数机场缺乏应对此类网络攻击的必要手段。这些缺失的手段不是技术工具,而是机场网络安全的整体监管指令、技术和流程标准、指南和最佳实践——在某些情况下,甚至连机场网络安全概念和基本定义都缺失了。与机场网络安全标准和监管有关的未解决话题提供了对这些问题及其原因的深入分析,重点是机场的总体独特性、具体的网络安全挑战、缺失的定义,以及机场网络安全标准化和监管的概念基础设施。 最后一项包括与机场网络安全相关的现有指南、最佳实践、标准和法规中的差距和挑战。最后,提出了实用的解决方案寻求过程,以及一些特定的潜在框架和解决方案。
A large international airport is a microcosm of the entire aviation sector, hosting hundreds of different types of aviation and non-aviation stakeholders: aircraft, passengers, airlines, travel agencies, air traffic management and control, retails shops, runway systems, building management, ground transportation, and much more. Their associated information technology and cyber physical systems--along with an exponentially resultant number of interconnections--present a massive cybersecurity challenge. Unlike the physical security challenge, which was treated in earnest throughout the last decades, cyber-attacks on airports keep coming, but most airport lack essential means to confront such cyber-attacks. These missing means are not technical tools, but rather holistic regulatory directives, technical and process standards, guides, and best practices for airports cybersecurity--even airport cybersecurity concepts and basic definitions are missing in certain cases.Unsettled Topics Concerning Airport Cybersecurity Standards and Regulationoffers a deeper analysis of these issues and their causes, focusing on the unique characteristics of airports in general, specific cybersecurity challenges, missing definitions, and conceptual infrastructure for the standardization and regulation of airports cybersecurity. This last item includes the gaps and challenges in the existing guides, best-practices, standards, and regulation pertaining to airport cybersecurity. Finally, practical solution-seeking processes are proposed, as well as some specific potential frameworks and solutions.
分类信息
关联关系
研制信息
相似标准/计划/法规