Welcome to the Industrial Automation website!

NameDescriptionContent
HONG  KANG
E-mail  
Password  
  
Forgot password?
  Register
当前位置:

Open a new stage in the security protection of critical information infrastructure

来源: | 作者:佚名 | 发布时间 :2023-12-05 | 109 次浏览: | Share:

First, legislation on the security protection of critical information infrastructure is an important part of each country's cybersecurity strategy

(1) The complex and grave global cyber security situation poses new challenges to the security and protection of critical information infrastructure in all countries. Recently, the infrastructure and important information systems of many countries have been subjected to cyber attacks, causing global shock and posing huge risks to national security and stability. In particular, in 2021, the largest fuel pipeline operator in the United States and the world's largest meat processing enterprises were shut down due to hacker attacks, resulting in damage to infrastructure affecting the operation of the national and even global economy, having a chain impact on the whole industrial chain, and triggering global thinking on strengthening the security protection of critical information infrastructure. Recently, major countries and regions in the world have strengthened the security protection of critical infrastructure. The United States not only significantly increased funding for critical infrastructure cybersecurity, but also proposed a number of bills and official guidelines to strengthen critical infrastructure cybersecurity and prevent ransomware attacks. The EU has also made improving the protection and resilience of critical infrastructure a top priority for cybersecurity over the next five years in the EU Security Union Strategy.

(2) Major countries and regions in the world have taken critical infrastructure legislation as the most critical link in cybersecurity legislation. The United States and Europe started earlier in critical infrastructure legislation. The United States promulgated the Critical Infrastructure Protection Act of 2001 as early as 2001, followed by the Executive Order on Improving Critical Infrastructure Network Security and the Executive Order on Enhancing Federal Government Network and Critical Infrastructure Network Security. With the increasingly severe cybersecurity situation, the United States has actively adjusted its cybersecurity protection strategy, and recently issued the Interim National Security Strategic Guideline for 2021 and the Executive Order on Strengthening National Cybersecurity for 2021. The EU has introduced several pieces of legislation related to the protection of critical infrastructure, including the 2008 EU Directive on the Identification and Security Assessment of Critical Infrastructure and the 2016 Directive on Network and Information Security. Russia enacted the Federal Critical Information Infrastructure Security Act in 2017, and Australia enacted the Critical Infrastructure Security Act in 2018. In addition, the United Kingdom, Germany, Japan and other countries have also introduced relevant legislation and policies for the protection of critical infrastructure.

(3) China's cybersecurity Law emphasizes a higher level of protection for critical information infrastructure. On the basis of clarifying the basic system of national network security, China's cybersecurity Law introduced in 2016 stipulates a higher level of security protection requirements for critical information infrastructure. The Cybersecurity Law provides for the key protection of critical information infrastructure, and in Chapter 3, "Network Operation Security", a single section is set up to specifically provide for the security protection of critical information infrastructure. Higher requirements are put forward for security management measures such as technical measures, personnel mechanisms, data security, and risk assessment involved in the security protection of critical information infrastructure, and it is emphasized that the security protection system of critical information infrastructure should be further improved through supporting legislation, highlighting the important position of critical information infrastructure in the overall national network security system.

The Regulations establish specific institutional requirements for the security protection of China's critical information infrastructure

The Cybersecurity Law makes general provisions on the relevant implementation objects, responsibility subjects, and work contents of the security protection system for critical information infrastructure. As an important supporting regulation of the Cybersecurity Law, the Regulations are implemented based on work and define a series of basic elements related to the security protection of critical information infrastructure such as the scope of application, regulatory subjects, and assessment objects. Security protection requirements and security measures are put forward to ensure specific objects, clear rights and responsibilities, and clear tasks, and to provide systematic guidance and work compliance for security protection work.

(1) Determine the scope of protected objects. Article 2 of the Regulations gives a clear definition of critical information infrastructure, Article 9 puts forward the key considerations for the protection work department to formulate identification rules, and determines that the protection work department is responsible for formulating the identification rules and lists of critical information infrastructure in the industry and the field. On the one hand, the formation process of the identification rules and lists must be based on the reality, fully combined with the characteristics and importance of the industry and the field of business, and achieve the accurate definition of the scope of the list on the basis of quantitative index parameters; On the other hand, the list should be dynamically adjusted and updated along with the development of national cybersecurity and informatization.

(2) Clarify the division of oversight responsibilities. In order to ensure the smooth development of the security protection of critical information infrastructure, the Regulations set up a scientific and rigorous supervision and management mechanism. At the national level, the national network information department is responsible for overall coordination, the public security department of The State Council is responsible for guidance and supervision, and the telecommunications department of The State Council and other relevant departments are responsible for the security protection, supervision and management of key information infrastructure of the industry; At the local level, the relevant departments of the provincial people's governments are responsible for the security protection, supervision and management of critical information infrastructure. It not only effectively ensures the unified, orderly and coordinated promotion of the security protection of critical information infrastructure, but also gives full play to the professional advantages of specific industry sectors to improve the security protection of critical information infrastructure.

3. Strengthening primary responsibility for security. The Regulations emphasize that critical information infrastructure operators (hereinafter referred to as operators) assume the main responsibility for the security protection of critical information infrastructure, and set strict requirements for the operators' own security management mechanism. The first is to emphasize the responsibility of the main person in charge, and make it clear that the main person in charge of the operator is responsible for the security protection of critical information infrastructure. The second is to require the establishment of a special security management organization, which is specifically responsible for the security protection of the critical information infrastructure of the unit. The third is the implementation of security background checks for personnel in key positions, including the person in charge of the operator's special safety management agency and the personnel identified as key positions. The fourth is to ensure the operation of the special safety management agency, and provide funds and professional personnel protection for the special safety management agency of the unit.

(4) Detailed security protection requirements. The Regulations strengthen the security protection of critical information infrastructure and put forward higher security protection requirements for operators on the basis of the Network Security Law. The first is to implement the "three synchronization" requirements, requiring security protection measures and critical information infrastructure synchronous planning, synchronous construction, synchronous use, critical information infrastructure from the date of inclusion in the list of key information infrastructure, in the design and construction (expansion), operation and maintenance, emergency recovery, decommissioning and waste stages, should ensure the implementation of security protection covering the whole life cycle. The second is to carry out regular security testing and risk assessment, and the operator must carry out network security testing and risk assessment at least once a year, which can be carried out by itself or commissioned by network security service agencies. The third is to fulfill the obligation of reporting security incidents and threats, in the event of a major cybersecurity incident or the discovery of a major cybersecurity threat, the operator shall report to the relevant departments. The fourth is to implement the requirements of network security review, operator procurement of network products and services may affect national security, should be in accordance with the national network security provisions for security review. Fifth, to strengthen monitoring and early warning and information sharing, the Regulations propose to establish and improve the network security monitoring and early warning system for critical information infrastructure, accurately grasp the operation of critical information infrastructure, and promote network security information sharing.

5. Strengthening key security guarantees. First, the implementation of vulnerability detection, penetration testing and other activities for critical information infrastructure should be approved by the national network information department, the public security department of The State Council, or authorized by the protection department and the operator. Activities such as vulnerability detection and penetration testing of basic telecommunications networks shall be reported to the competent department of telecommunications under The State Council in advance. Second, the energy and telecommunications industries provide important support and resource guarantee for the stable operation of key information infrastructure in finance, water conservancy, transportation and other industries, and the basic telecommunications network is also basic and global, carrying other key information infrastructure. The state will take measures to give priority to the safe operation of key information infrastructure such as energy and telecommunications. The energy and telecommunications industries will provide key guarantees for the safe operation of critical information infrastructure in other industries and fields.

Third, the new stage of critical information infrastructure security protection

1. Improving the system of supporting standards and regulations. First, accelerate the formulation and introduction of national standards around the common security needs and baseline security requirements of critical information infrastructure. Second, the protection work department focuses on the actual conditions and characteristics of the industry, deeply promotes the construction of key information infrastructure standards in the industry, and organizes the implementation. The third is to carry out in-depth research on the management mechanism in key aspects such as operators' responsibilities and obligations, information sharing mode, collaborative disposal mechanism, and security protection capability identification.

(2) Deepening the implementation of industry supervision responsibilities. The first is to guide and supervise the industry operators to implement the main responsibility of security, and do a solid job in the security protection of key information infrastructure such as network security threat monitoring and disposal, network security review. The second is to improve the supervision and inspection mechanism, and strengthen the security protection inspection and risk assessment of key information infrastructure in the industry. The third is to build and improve the emergency support system, establish technical support means such as situational awareness and emergency command, organize and carry out scenario-based, thematic and joint emergency drills, and build a team of experts.

3. We will strengthen demonstrations of the application of new technologies and models. First, strengthen research on innovation and development, and actively use new technologies such as cloud computing, big data, and artificial intelligence to enhance the cybersecurity capabilities of critical information infrastructure. The second is to establish an innovation incentive mechanism, deepen the innovative application and pilot demonstration of advanced cybersecurity technologies, gather the strength of the cybersecurity industry, and strengthen the supply of cybersecurity capabilities for critical information infrastructure. The third is to carry out the assessment and continuous optimization of the network security capability of critical information infrastructure, and objectively assess the level of network security capability. Choose the direction of improving security capability in a scientific way.


  • Honeywell TK-IAH161 - 1PC ANALOG INPUT New Shipping DHL or FedEX
  • Honeywell PX45A - "8 Points/mm (203dpi), Rewind, LTS, Disp. (Color), RTC, Ethernet,"
  • Honeywell 51309276-150 - / 51309276150 (NEW NO BOX)
  • Honeywell 82408217-001 - / 82408217001 (NEW NO BOX)
  • Honeywell BK-G100 - Elster U160 Gas Meter DN100 #3485
  • Honeywell MIDAS-M - 1PC MMC-A2U20000 Detector (DHL or FedEx) #H254CC YD
  • Honeywell 621-9938R-RP - Serial Input/Output Module 22572 Vr 3.2 94V-0
  • Honeywell U2-1018S-PF - NEW flame detector DHL Fast delivery
  • Honeywell TK-PRR021 - 51309288-475 redundancy module
  • Honeywell 50129828-003 - Temperature Transmitter
  • Honeywell 3151080 - RING SET P/N (HONEYWELL) NS COND # 11344 (4)
  • Honeywell 4DP7APXPR311 - CIRCUIT BOARD
  • Honeywell MG-818 - Symbol Generator P/N 7011675-818
  • Honeywell TC-IAH161 - NEW PLC Module One year Warranty#XR
  • Honeywell 51304800-100 - 30731808-004 Regulator Card REV B
  • Honeywell MU-FOED02 - UCN EXTENDER PN:51197564-200 REV F
  • Honeywell MC-PAIL02 - 51304907-100 Specii Input/Output Module Rev E
  • Honeywell SPS5713 - 51199930-100 NSMP
  • Honeywell XS858A - Mode S Transponder 7517401-960 Removed Working
  • Honeywell SK-5208 - Fire Panel Maintenance Service 6MonWarri UPS Express SK5208 Zy
  • Honeywell 51403422-150 - NEW HDW COMM CTRL CONTROLLER
  • Honeywell IBI-AD - Yamatake- 82407390-001/ 82408215-001 PCB Card
  • Honeywell 51401635-150 - / 51401635150 (USED TESTED CLEANED)
  • Honeywell ANT67A - TCAS Antenna 071-01548-0100 w/ March 2024 Overhauled 8130
  • Honeywell TC-IAH161 - NEW PLC Module One year Warranty
  • Honeywell 620-3632C - CPU. . (UK And EU Buyers Read)
  • Honeywell PX45A - "12 Points/mm (300dpi), Rewind, LTS, Disp. (Color), RTC, Ethernet"
  • Honeywell K4LCN-4 - 51402755-100 Processor Card Rev: F 51305099-100 B
  • Honeywell 2001-400-150-126-200-20-100001-1-0-00 - REPAIRED PNEUMATIC ACTUATOR
  • Honeywell GGSI - 51401914-100 HDW B FW A R400 51400996-100 Rev C PLC Board Module
  • Honeywell 184637 - TRANSDUCER P/N (HONEYWELL) NS CONDITION #12517
  • Honeywell WEB-600E - Network Controller Via DHL or FedEx
  • Honeywell 620-0073C - / 6200073C (USED TESTED CLEANED)
  • Honeywell 05704-A-0144 - / 05704A0144 (NEW NO BOX)
  • Honeywell RI-406 - P/N 4026206-940 (Sperry) Instrument Remote Controller
  • Honeywell AAU-32/A - ALTIMETER ENCODER P/N 99251-3252011-0101 REP TAG # 12197
  • Honeywell T-1204-1174 - 51304907-100 Spcii I/O Module
  • Honeywell TK-PRS021 - Control Processor Expedited Shipping TKPRS021 Spot Goods Zy
  • Honeywell VITO - Enraf Lt Interface 762 Up 762 Aga / Z
  • Honeywell QPP-0001 - FC-QPP-0001 Module
  • Honeywell TC-PRS021 - / TCPRS021 (USED TESTED CLEANED)
  • Honeywell 51403698-100 - / 51403698100 (USED TESTED CLEANED)
  • Honeywell XCL8010A - 24V NSMP
  • Honeywell 91884 - "Target, 15.620 X 12.846 X 0.250"" BTL, 07-613, 5N TI, 118305"
  • Honeywell 51403776-100 - / 51403776100 (USED TESTED CLEANED)
  • Honeywell LG1093AC01 - UV Flame Sensor/Detector
  • Honeywell CC-PCNT02 - Controller Module Expedited Shipping CCPCNT02 Spot Goods Zy
  • Honeywell FFSB14ER10KS2 - / FFSB14ER10KS2 (NEW IN BOX)
  • Honeywell RF600 - Radio Frequency Unit 7516240-60060 Removed Working
  • Honeywell 51196881-100 - NEW UPGRADE KIT EC W/ODEP 51196881100
  • Honeywell CC-IP0101 - 51410056-175 Brand New Expedited Shipping
  • Honeywell AL300 - Alt Preselect Command Controller 7002412-904 w/ August 2011 Repaired 8130
  • Honeywell 094377-00 - / 09437700 (USED TESTED CLEANED)
  • Honeywell IRTP271 - Tata Printed Circuit Board Rev.0 DPCB21010003
  • Honeywell TVMUGR-888880-020-52-3-030-0U000G-000 - MULTITREND GR GRAPHIC RECORDER
  • Honeywell RM850 - Radio Management Unit 7012100-811 w/ December 2017 Repaired 8130
  • Honeywell PGM-7360 - Gas Detector
  • Honeywell WU660 - Radar RTA 7021450-601 w/ April 2024 Overhauled 8130
  • Honeywell 9243201 - / 9243201 (NEW NO BOX)
  • Honeywell AZ850 - Micro Air Data Computer 7014700-601 Removed Working
  • Honeywell DCP550 - Yamatake- Digital Programmable Controller Temperature
  • Honeywell FF-SEDGE6G2-1M-C - / FFSEDGE6G21MC (USED TESTED CLEANED)
  • Honeywell FC-RUSIO-3224 - Brand New Expedited Shipping Via DHL
  • Honeywell RM850 - Radio Management Unit 7012100-801 w/ March 2021 Tested 8130
  • Honeywell HIMA-6E-B - Large System Controller Via DHL or FedEx
  • Honeywell RM855 - Radio Management Unit 7013270-973 w/ April 2024 Modified 8130
  • Honeywell MP-DNCF02-200 - REV B Upper & Lower / 51305072-300 51305072-200 REV L.
  • Honeywell 80360206-001 - / 80360206001 (USED TESTED CLEANED)
  • Honeywell DE132-0-A-BB-0-Z-1-0C-EE0-00 - Chart Recorder
  • Honeywell 51403519-160 - NSNP
  • Honeywell 627-1002RC - / 6271002RC (USED TESTED CLEANED)
  • Honeywell 51400997-100 - / 51400997100 (USED TESTED CLEANED)
  • Honeywell J-AOM10 - Yamatake- /J-A0M10 Analog Output Module 24Vdc 480Ma Hw/Fw Rev: C
  • Honeywell AZ800 - Digital Air Data Computer 7000700-953 w/ July 2016 Repaired EASA Form 1
  • Honeywell FC-RUSIO-3224 - Brand New
  • Honeywell BZ-2RW82272-A2 - Micro Switch 1a 125vac
  • Honeywell FC-RUSIO-3224 - 1PC Brand New
  • Honeywell 10268S-1-020-201-0-2-03100-000-00 - Electric Actuator 121va 120v-ac
  • Honeywell 14CE102-1RS - Limit Switch IP65
  • Honeywell FC-PSU-UNI2450U - Brand New Fast Shipping FedEx or DHL
  • Honeywell 696658-1 - SUPPORT ASSY. NS 11764 (3)
  • Honeywell TK-PRR021 - ONE New 51309288-475 DC
  • Honeywell PSU-UNI2450 - (AS PICTURED) NUPI
  • Honeywell 80360146-011 - / 80360146011 (USED TESTED CLEANED)
  • Honeywell EGWPM - MODULE Assembly 7028419-1904 Inspected/Tested Jun. 2021
  • Honeywell DE131-0-A-0B-0-Z-1-0B,0C-EE0-000 - "Chart Recorder"
  • Honeywell 51454493-126 - / 51454493126 (NEW IN BOX)
  • Honeywell 965-1186-003 - "MK VI, GPWS Computer, EASA FORM ONE/FAA 8130 Guaranteed"
  • Honeywell 51401996-100 - / 51401996100 (USED TESTED CLEANED)
  • Honeywell TSENALMOX-08287 - "Target, 1.900 X 12.733 X 15.620"", 037-173-53, 118222"
  • Honeywell SPS5785 - 1pc 51198651-100 Power Supply Brand New Fast shipping
  • Honeywell FX-USI-0002 Security Manager System Module 5Vdc
  • Honeywell SPS5785 - 51198651-100 power supply
  • Honeywell HIMA-6E-B - Large System Controller Fast Shipping
  • Honeywell 51301882-100 - RTD MUX Terminal Board
  • Honeywell 51198821-100 - 1PC new module PLC One year warranty free Shipping#XR
  • Honeywell EAMR - 51401996-100 E CARD card
  • Honeywell 51305734-100 - / 51305734100 (USED TESTED CLEANED)
  • Honeywell 50065674 - Basic Display PWA Assembly HNWG50049911-001
  • Honeywell TSENCOBTM-07889 - "15.620X12.913X0.125 MPS-5-002/M TARGET, 109953"
  • Honeywell 86220000 - / 086220000 (USED TESTED CLEANED)
  • Honeywell CC-IP0101 - C300 system card Brand new fedex or DHL
  • Honeywell WU880 - Radar Antenna 7021450-801 w/ May 2024 Repaired 8130
  • Honeywell CC-IP0101 - ONE Profibus DP Gateway Module NEW
  • Honeywell 397124-2-4 - Gulfstream Valve New Overhauled
  • Honeywell PGM-7340 - RAE 3000 VOC Detector Shipping DHL or FedEX
  • Honeywell RCZ850 - Integrated Communication Unit 7510100-731 w/ March 2024 Tested 8130
  • Honeywell STS103-001-00006-12-1137 - NSNP
  • Honeywell AL300 - Altitude Preselect Command Ctlr 7002412-906 w/ March 2024 Overhauled 8130
  • Honeywell 2119020-8000 - Series 1 N1 Digital Electronic Engine Control
  • Honeywell 51198685-100 - Power Module Brand New Shipping FedEx or DHL
  • Honeywell 620-0073C - / 6200073C (NEW IN BOX)
  • Honeywell GTS-3PA-B - "Timer 0-60 Sec, 220v 50/60 Hz"
  • Honeywell IVA81D - TCAS Vertical Speed Indicator 066-01171-2804 w/ January 2020 Tested 8130
  • Honeywell 51403299-200 - / 51403299200 (NEW NO BOX)
  • Honeywell TSENALMOX-08287 - "Target, 1.900 X 12.733 X 15.620"", 037-173-53, 118221"
  • Honeywell AT860 - Loop Sense Antenna 7510300-901 w/ May 2024 Tested 8130
  • Honeywell XL2000B3A - 1PCS USED /
  • Honeywell CC-PCNT02 - C300 Controller Module
  • Honeywell ASDX015D44R - SenSym Pressure Sensor Micro Switch 0-15 psi 8 pin DIP
  • Honeywell 900CS15-00 - Touch Panel NEW SHIP DHL OR EMS 1 Year Warranty cl
  • Honeywell FC-SCNT01 - S300 Control Module 51454926-176 Security Control - 400mA
  • Honeywell DC1010CR-301000-E - Digital Temperature Controller 85-265VAC
  • Honeywell TK-PRR021 - redundancy module 51309288-475
  • Honeywell K4LCN - 51402755-100 Motherboard SS 51201795-400
  • Honeywell XL2000B3A - plc new FREE EXPEDITED SHIPPING
  • Honeywell FC-SCNT02 - 51460114-176 S300 Controller Module 78-4
  • Honeywell BVS - 99ATEX2259X 03ATEXG016X Tester new