Quantification of Human Errors in Cyber Security in the Nuclear Sector
Quantification of Human Errors in Cyber Security in the Nuclear Sector
批准号:
133470
负责人:
金额:
$8.9万
依托单位国家:
英国
项目类别:
Feasibility Studies
财政年份:
2018
资助国家:
英国
项目状态:
已结题
起止时间:
2018 至 --
中文摘要
“英国的民用核安全战略(2017年2月)将CS和混合攻击确定为一个主要问题,并建议英国核部门和相关供应链的组织应该增加对CS风险的理解,并减轻安全漏洞。在CyberUK 2017上,NCSC以人为本的安全负责人发表了与英国国家战略相关的主题演讲,并重点介绍了人员在预防这些攻击方面所发挥的重要作用。人工任务包括识别和响应攻击、维护防御屏障、监控人员、决策和态势感知,以及避免无意中削弱这些防御。人为错误,包括无意的错误和违规,是出于非恶意原因(例如,因为某人认为没有必要)而采取的不符合规定方法或组织政策的有意识行为。这两种情况在许多csb中都有涉及,因此,了解潜在的人为因素问题将使评估人员能够识别会增加人为错误风险的任务特性。该项目将开发一种结构化的方法,以研究人类在认知优势、局限性和表现塑造因素方面的能力为基础。将开发的工具将使核设施能够量化CSB预防任务的风险,从而可以确定任何弱点,并减少损害CSB的人为错误的风险。开发的工具将涵盖防止计算机攻击或混合攻击的硬件或软件以物理方式或通过互联网进入核设施的任务;访问控制任务;监控互联网流量,如有必要,在发生攻击时采取有效的预防措施。该项目将由CRA承担,他们是风险管理、人为因素和人的可靠性分析领域的知名专家,特别是在核领域。先进的计算机安全专业知识来自肯特大学,该大学是网络安全研究卓越学术中心(ACE CSR)机构的一部分。”
英文摘要
"The UK's Civil Nuclear Security Strategy (Feb 2017) identifies CS and blended attacks as being a major concern and proposes that organisations in the UK Nuclear Sector and the associated supply chain should increase their understanding of CS risks and mitigate security vulnerabilities. At CyberUK 2017, the NCSC People-Centred Security Lead presented a keynote speech linked to the UK national strategy and the focus on the essential roles that personnel take in preventing these attacks. Human tasks include identifying and responding to attacks, maintaining defensive barriers, monitoring personnel, decision-making and situation awareness and avoiding inadvertently weakening these defences.Human errors, including both unintentional errors and violations, which are conscious acts that do not conform to the prescribed methods or organisational policies that are undertaken for non-malicious reasons (e.g. because a person does not consider them to be necessary). Both of these have been implicated in many CSBs and so, understanding the underlying human factors issues will enable assessors to identify the task features that will increase the risk of human errors. This project will develop a structured approach underpinned by research into human capabilities in terms of cognitive strengths, limitations and performance shaping factors.The tool that will be developed will enable nuclear installations to quantify the risks for CSB prevention tasks, so that any weaknesses can be identified and the risk of human errors that compromise CS can be reduced. The tool that is developed will cover tasks to prevent hardware or software for a CS or blended attack from entering a nuclear site physically or via the internet; access control tasks; monitoring internet traffic and if necessary, undertaking effective preventive actions in the event of an attack.The project will be undertaken by CRA who are renowned experts in the field of risk management, human factors and human reliability analysis, especially in the nuclear arena. Advanced CS expertise comes from the University of Kent which is part of the Academic Centres of Excellence in Cyber Security Research (ACE CSR) institution."
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
靶向Human ZAG蛋白的降糖小分子化合物筛选以及疗效观察
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:胡文静
-
依托单位:
HBV S-Human ESPL1融合基因在慢性乙型肝炎发病进程中的分子机制研究
-
批准号:81960115
-
项目类别:地区科学基金项目
-
资助金额:34.0万元
-
批准年份:2019
-
负责人:江建宁
-
依托单位:
基于自适应表面肌电模型的下肢康复机器人“Human-in-Loop”控制研究
-
批准号:61005070
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2010
-
负责人:李庆玲
-
依托单位: