Critical Infrastructure Protection and Supply Chain Risk Management

被引:1
|
作者
Mead, Nancy R. [1 ]
机构
[1] Carnegie Mellon Univ, Inst Software Res, Pittsburgh, PA 15213 USA
关键词
cybersecurity; critical infrastructure protection; supply chain risk management; security requirements;
D O I
10.1109/REW56159.2022.00047
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Critical infrastructure is a key area in cybersecurity. In the U.S., it was front and center in 1997 with the report from the President's Commission on Critical Infrastructure Protection (PCCIP), and now affects countries worldwide. Critical Infrastructure Protection must address all types of cybersecurity threats - insider threat, ransomware, supply chain risk management issues, and so on. Unsurprisingly, in the past 25 years, the risks and incidents have increased rather than decreased and appear in the news daily. As an important component of critical infrastructure protection, secure supply chain risk management must be integrated into development projects. Both areas have important implications for security requirements engineering.
引用
收藏
页码:215 / 218
页数:4
相关论文
共 50 条