信息网络安全 ›› 2023, Vol. 23 ›› Issue (8): 121-127.doi: 10.3969/j.issn.1671-1122.2023.08.011

• 理论研究 • 上一篇    

水利关键信息基础设施安全保护探索与实践

付静()   

  1. 水利部信息中心,北京 100053
  • 收稿日期:2023-04-07 出版日期:2023-08-10 发布日期:2023-08-08
  • 通讯作者: 付静 E-mail:fujing@mwr.gov.cn
  • 作者简介:付静(1976—),女,北京,正高级工程师,硕士,主要研究方向为水利网络安全和信息化。

Exploration and Practice of Security Protection of Critical Information Infrastructure of Water Conservancy

FU Jing()   

  1. Information Center of Ministry of Water Resources, Beijing 100053, China
  • Received:2023-04-07 Online:2023-08-10 Published:2023-08-08
  • Contact: FU Jing E-mail:fujing@mwr.gov.cn

摘要:

水利是国家关键信息基础设施保护的重要行业之一,因此,对其开展网络安全保护研究是十分迫切且必要的。文章阐述了水利关键信息基础设施安全保护的法律法规和标准规范要求,总结了水利行业的保护基础和面临的风险挑战。在此基础上,文章提出了以完善组织管理体系、创新安全技术体系、强化监督检查体系和规范安全运营体系为主体,提升监测预警、纵深防御、应急响应和实战对抗4项能力的水利网络安全综合防御架构。同时,文章提出了网络IPv6升级、国产密码数据保护和水利工控分区管控等关键技术路径及应用,可为行业网络安全建设提供指引和参考。

关键词: 水利关键信息基础设施, 关键信息基础设施安全保护, 网络安全

Abstract:

Water conservancy is one of the important industries of national critical information infrastructure, so it is very urgent and necessary to carry out water conservancy research and application of network security protection. This paper expounded the laws, regulations and standard requirements for the security protection of critical information infrastructure of water conservancy, and summarized the protection basis and the risks and challenges faced by the water conservancy industry. On this basis, a comprehensive water conservancy network security system was proposed that focused on improving the organizational management system, innovating the security technology system, strengthening the supervision and inspection system, which standardizing the security operation system, and improving the four capabilities of monitoring and early warning, defense in depth, emergency response, and actual combat confrontation. At the same time, this paper proposed critical technical paths and applications such as network IPv6 upgrade, domestic password data protection, and water conservancy industrial control partition management and control, which can provide guidance and reference for the construction of industry network security.

Key words: critical information infrastructure of water conservancy, security protection of critical information infrastructure, network security

中图分类号: