论文标题

船上运营技术系统中的网络风险管理指南

Guidelines for cyber risk management in shipboard operational technology systems

论文作者

Rajaram, Priyanga, Goh, Mark, Zhou, Jianying

论文摘要

在过去的几年中,我们已经看到了几起网络事件,其中一些主要原因是船上缺乏适当的安全控制,以及机组人员对网络安全的认识。为了响应海上行业不断增长的网络威胁格局,我们制定了一套海上网络风险管理指南,重点关注四种对于船舶日常运营至关重要的四种主要的船舶运营技术(OT)系统。这四个OT系统是:通信系统,推进,机械和电源控制系统,导航系统和货物管理系统。该指南确定了每个OT系统中的网络风险,并建议可以采取必要的措施来管理每个船上OT系统中的风险。在本文中,我们介绍了新的指南,其中包括网络风险,缓解措施,网络风险评估以及清单,以帮助船东和海上当局评估和增强其船舶的网络卫生。我们的指南已由新加坡海事和港口管理局(MPA)传播给新加坡注册处的所有者和运营商,以供其参考和使用。

Over the past few years, we have seen several cyber incidents being reported, where some of the primary causes were the lack of proper security controls onboard the ship and crew awareness on cybersecurity. In response to the growing cyber threat landscape in the maritime sector, we have developed a set of guidelines for maritime cyber risk management, focusing on four major shipboard Operational Technology (OT) systems that are crucial for the day-to-day operation of ships. These four OT systems are: Communication Systems, Propulsion, Machinery and Power Control Systems, Navigation Systems and Cargo Management Systems. The guidelines identify the cyber risks in each of the OT systems and recommend the necessary actions that can be taken to manage risks in each shipboard OT system. In this paper, we introduce the new guidelines, which include cyber risks, mitigation measures, cyber risk assessment, and a checklist to help shipowners and maritime authorities assess and enhance cyber hygiene of their vessels. Our guidelines have been disseminated by the Maritime and Port Authority of Singapore (MPA) to owners and operators of the Singapore Registry of Ships for their reference and use.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源