CERP:海上网络风险决策工具

E. Erstad, R. Hopcraft, Juan Dorje Palbar, K. Tam
{"title":"CERP:海上网络风险决策工具","authors":"E. Erstad, R. Hopcraft, Juan Dorje Palbar, K. Tam","doi":"10.12716/1001.17.02.02","DOIUrl":null,"url":null,"abstract":": An increase in the complexity of systems onboard ships in the last decade has seen a rise in the number of reported maritime cyber ‐ attacks. To tackle this rising risk the International Maritime Organization published high ‐ level requirements for cyber risk management in 2017. These requirements obligate organisations to establish procedures, like incident response plans, to manage cyber ‐ incidents. However, there is currently no standardised framework for this implementation. This paper proposes a Cyber Emergency Response Procedure (CERP), that provides a framework for organisations to better facilitate their crew’s response to a cyber ‐ incident that is considerate of their operational environment. Based on an operations flowchart, the CERP provides a step ‐ by ‐ step procedure that guides a crew’s decision ‐ making process in the face of a cyber ‐ incident. This high ‐ level framework provides a blueprint for organisations to develop their own cyber ‐ incident response procedures that are considerate of operational constraints, existing incident procedures and the complexity of modern maritime systems.","PeriodicalId":46009,"journal":{"name":"TransNav-International Journal on Marine Navigation and Safety of Sea Transportation","volume":"8 1","pages":""},"PeriodicalIF":0.7000,"publicationDate":"2023-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"CERP: A Maritime Cyber Risk Decision Making Tool\",\"authors\":\"E. Erstad, R. Hopcraft, Juan Dorje Palbar, K. Tam\",\"doi\":\"10.12716/1001.17.02.02\",\"DOIUrl\":null,\"url\":null,\"abstract\":\": An increase in the complexity of systems onboard ships in the last decade has seen a rise in the number of reported maritime cyber ‐ attacks. To tackle this rising risk the International Maritime Organization published high ‐ level requirements for cyber risk management in 2017. These requirements obligate organisations to establish procedures, like incident response plans, to manage cyber ‐ incidents. However, there is currently no standardised framework for this implementation. This paper proposes a Cyber Emergency Response Procedure (CERP), that provides a framework for organisations to better facilitate their crew’s response to a cyber ‐ incident that is considerate of their operational environment. Based on an operations flowchart, the CERP provides a step ‐ by ‐ step procedure that guides a crew’s decision ‐ making process in the face of a cyber ‐ incident. This high ‐ level framework provides a blueprint for organisations to develop their own cyber ‐ incident response procedures that are considerate of operational constraints, existing incident procedures and the complexity of modern maritime systems.\",\"PeriodicalId\":46009,\"journal\":{\"name\":\"TransNav-International Journal on Marine Navigation and Safety of Sea Transportation\",\"volume\":\"8 1\",\"pages\":\"\"},\"PeriodicalIF\":0.7000,\"publicationDate\":\"2023-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"TransNav-International Journal on Marine Navigation and Safety of Sea Transportation\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.12716/1001.17.02.02\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q4\",\"JCRName\":\"TRANSPORTATION SCIENCE & TECHNOLOGY\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"TransNav-International Journal on Marine Navigation and Safety of Sea Transportation","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.12716/1001.17.02.02","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"TRANSPORTATION SCIENCE & TECHNOLOGY","Score":null,"Total":0}
引用次数: 0

摘要

在过去的十年中,随着船上系统复杂性的增加,报告的海上网络攻击数量也有所增加。为了应对这一不断上升的风险,国际海事组织于2017年发布了网络风险管理的高级要求。这些要求要求组织建立程序,如事件响应计划,以管理网络事件。然而,目前还没有针对这种实现的标准化框架。本文提出了一个网络应急响应程序(CERP),该程序为组织提供了一个框架,以更好地促进其机组人员对考虑其操作环境的网络事件的响应。基于操作流程图,CERP提供了一个一步一步的程序,指导船员在面对网络事件时的决策过程。该高级框架为组织提供了一个蓝图,以开发他们自己的网络事件响应程序,这些程序考虑到操作限制、现有事件程序和现代海事系统的复杂性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
CERP: A Maritime Cyber Risk Decision Making Tool
: An increase in the complexity of systems onboard ships in the last decade has seen a rise in the number of reported maritime cyber ‐ attacks. To tackle this rising risk the International Maritime Organization published high ‐ level requirements for cyber risk management in 2017. These requirements obligate organisations to establish procedures, like incident response plans, to manage cyber ‐ incidents. However, there is currently no standardised framework for this implementation. This paper proposes a Cyber Emergency Response Procedure (CERP), that provides a framework for organisations to better facilitate their crew’s response to a cyber ‐ incident that is considerate of their operational environment. Based on an operations flowchart, the CERP provides a step ‐ by ‐ step procedure that guides a crew’s decision ‐ making process in the face of a cyber ‐ incident. This high ‐ level framework provides a blueprint for organisations to develop their own cyber ‐ incident response procedures that are considerate of operational constraints, existing incident procedures and the complexity of modern maritime systems.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
1.40
自引率
16.70%
发文量
22
审稿时长
40 weeks
期刊最新文献
The Concept of Determining the Ship’s Route Based on the Capability Plots The DIA-Method for Navigational Integrity Impact of Late and Early Fuel Injection on Main Engine Efficiency and Exhaust Gas Emissions Seeking the Best Practices of Assessment in Maritime Simulator Training Digital Transformation in Ferry Shipping – Case Study in the Baltic Sea Region
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1