郭云, 李江海. IEC 63096核电厂仪控系统网络安全管控标准与国内等级保护相关标准的协调分析[J]. 核科学与工程, 2024, 44(1): 161-167.
引用本文: 郭云, 李江海. IEC 63096核电厂仪控系统网络安全管控标准与国内等级保护相关标准的协调分析[J]. 核科学与工程, 2024, 44(1): 161-167.
GUO Yun, LI Jianghai. Analysis of the Coordination of IEC 63096 and National Standards for the Classified Protection of Cyber Security[J]. Chinese Journal of Nuclear Science and Engineering, 2024, 44(1): 161-167.
Citation: GUO Yun, LI Jianghai. Analysis of the Coordination of IEC 63096 and National Standards for the Classified Protection of Cyber Security[J]. Chinese Journal of Nuclear Science and Engineering, 2024, 44(1): 161-167.

IEC 63096核电厂仪控系统网络安全管控标准与国内等级保护相关标准的协调分析

Analysis of the Coordination of IEC 63096 and National Standards for the Classified Protection of Cyber Security

  • 摘要: 伴随着全球工业数字化、网络化和智能化的发展,传统基于物理隔离的保护方式已无法确保核电厂仪控系统的网络安全。核电厂仪控系统遭受网络攻击不仅可能导致生产过程中断,还可能引起核安全事件,因此核电厂仪控系统网络安全已引起世界各国及相关国际组织的高度关注。国际电工委员会于2020年发布了关于核电厂仪控系统网络安全防范管控的国际标准IEC 63096,为核电厂仪控系统各相关方提供了基于网络安全防范等级和生命周期阶段的具体指引,用于指导核电厂实施网络安全管控措施,以预防、检测和处置网络攻击。同时,等级保护制度作为我国网络安全的基础制度,是国内各核电厂必须开展的规定工作。为此,本文分别对IEC 63096以及等级保护系列标准进行了介绍,重点对二者在安全等级及管控措施方面的协调性进行了分析,从而帮助核电厂在进行网络安全管控措施的部署时有效降低时间成本和投资成本。

     

    Abstract: With the development of industrial digitalization, networking and intelligence, the security of I&C systems of nuclear power plants can’t be guaranteed using the traditional method based on physical isolation. Cyber attacks on I&Cs may cause the production process interruption and even nuclear safety incidents, thus attracting great attention of interested countries and organizations. In 2020, IEC issued IEC 63096 which provides specific guidance based on the security degree and life cycle aiming to help all parties involved in I&C implement security controls to prevent, detect and correct cyber attacks. Accordingly, China has been implementing classified protection system of cyber security for all industries including the nuclear power sector. This paper makes introduction respectively on the IEC 63096 and national classified protection standards, focuses on the analysis of coordination about the security degree and security controls between the two, so as to help NPPs in the deployment of security controls with relative low time costs and investment costs.

     

/

返回文章
返回