Комп’ютерна безпека інформаційних та керуючих систем АЕС: документи, що обґрунтовують комп’ютерну безпеку

The approaches to the development and management of computer security justification documents on computer security policy, program and plan, computer incident response plan, reports related to computer security are considered in the paper. Requirements for computer security policy, program and plan...

Повний опис

Збережено в:
Бібліографічні деталі
Дата:2019
Автори: Symonov, A., Klevtsov, O., Trubchaninov, S., Lazurenko, O.
Формат: Стаття
Мова:Ukrainian
Опубліковано: State Scientific and Technical Center for Nuclear and Radiation Safety 2019
Онлайн доступ:https://nuclear-journal.com/index.php/journal/article/view/191
Теги: Додати тег
Немає тегів, Будьте першим, хто поставить тег для цього запису!
Назва журналу:Nuclear and Radiation Safety

Репозитарії

Nuclear and Radiation Safety
Опис
Резюме:The approaches to the development and management of computer security justification documents on computer security policy, program and plan, computer incident response plan, reports related to computer security are considered in the paper. Requirements for computer security policy, program and plan are presented, and the analysis of different approaches adopted and reflected in the documents of the International Atomic Energy Agency, U.S. Nuclear Regulatory Commission and International Electrotechnical Commission is carried out. It is noted that the approaches used by these organizations to the development and management of computer security justification documents are quite similar. The paper provides suggestions for the development of requirements for computer security justification documents on the instrumentation and control systems at Ukrainian NPPs. The analysis of different international approaches to the development, implementation, and management of the computer security policy, program and plan has allowed developing requirements for the above-mentioned documents, which will be reflected in the new regulation taking into account the current situation at Ukrainian NPPs. Besides, it is planned to include separate requirements for computer security documentation of the developers of instrumentation and control systems regarding computer incident response plan and reporting documents on computer security in this regulation. The paper presents recommendations for the content, implementation and management of computer security justification documents.