|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/cybersecurity-policy-water-electricity
课程评论:没有评论
课程名称:水和电力基础设施的网络安全政策 概述:本课程将探讨饮用水和电力基础设施,以及为加强其网络安全项目而制定的各种政策。这两者是被称为“生命线基础设施”的十四个子部门之一。2013年国家基础设施保护计划确定了四个生命线基础设施领域:1)水,2)能源,3)运输,以及4)通讯。这些领域被称为“生命线”,因为许多其他基础设施依赖于它们。饮用水子部门是水领域的一部分,而电力子部门则是能源领域的一部分。两者均由国土安全部国家保护和项目局监管,该局负责管理DHS国家基础设施保护计划。NIPP实施采用一种称为风险管理框架的五步持续改进程序,由DHS指定的特定领域机构监管,这些机构由不同的联邦部门工作人员组成。特定领域机构与行业代表自愿合作,应用风险管理框架,并在相应的特定领域计划中记录结果。该项目始于2007年,最近的特定领域计划于2016年发布。2013年2月,奥巴马总统发布了第13636号行政命令,指示国家标准与技术研究所制定一套自愿的建议,以加强基础设施网络安全措施。EO13636还要求具有监管权的联邦机构建议NIST网络安全框架是否应当强制实施。负责饮用水子部门的环境保护局建议自愿应用NIST网络安全框架,而负责电力子部门的能源部则表示已在实施电力子部门网络安全能力成熟度模型(ES-C2M2),该模型实际上是基于NIST网络安全框架的。能源部也建议自愿应用ES-C2M2。本模块将研究饮用水和电力生命线基础设施子部门,以及NIST网络安全框架和ES-C2M2的要素及应用。 教学大纲: - 模块5:水基础设施与NIST网络安全框架 - 描述:本模块将研究饮用水子部门及NIST网络安全框架,以加强该基础设施的网络安全实践。 - 模块6:应用NIST网络安全框架 - 描述:本模块将更仔细地探讨NIST网络安全框架,并将其原则应用于不同的假设情境。同时包括课程考试#3。祝好运! - 模块7:电力基础设施与ES-C2M2 - 描述:本模块将研究北美电网和电力子部门网络能力成熟度模型(ES-C2M2),以加强该基础设施的网络安全实践。 - 模块8:应用ES-C2M2 - 描述:本模块将深入探讨电力子部门网络能力成熟度模型,并将其原则应用于不同的假设情境。同时包括课程考试#4和相关的项目作业。祝好运!
Name:Module 5: Water Infrastructure & NIST Cybersecurity Framework
Description:In this module we will examine the drinking water subsector and the NIST Cybersecurity Framework for strengthening this infrastructure's cybersecurity practices.
Name:Module 6: Applied NIST Cybersecurity Framework
Description:In this module we will take a closer look at the NIST Cybersecurity Framework and apply its tenets to different hypothetical situations. Also included in this module is course exam #3. Good luck!
Name:Module 7: Electricity Infrastructure & ES-C2M2
Description:In this module we will examine the North American electric grid and the Electricity Subsector Cyber Capability Maturity Model for strengthening this infrastructure's cybersecurity practices.
Name:Module 8: Applied ES-C2M2
Description:In this module we will take a closer look at the Electricity Subsector Cyber Capability Maturity Model and apply its tenets to different hypothetical situations. Also included in this module is course exam #4 and related project assignment. Good luck!
This course will examine the drinking water and electricity infrastructures, and various policies that have been developed to help guide and strengthen their cybersecurity programs. The drinking water and electricity infrastructures are two of fourteen subsectors comprising what are known as "lifeline infrastructure". The 2013 National Infrastructure Protection Plan identifies four lifeline infrastructure sectors: 1) water, 2) energy, 3) transportation, and 4) communications. These sectors are designated "lifeline" because many other infrastructures depend upon them. The drinking water subsector is part of the water sector, and the electricity subsector is part of the energy sector. Both subsectors are overseen by the Department of Homeland Security National Protection and Programs Directorate which manages the DHS National Infrastructure Protection Program. The NIPP employs a five-step continuous improvement program called the Risk Management Framework. NIPP implementation is overseen by DHS-designated Sector-Specific Agencies staffed by various Federal departments. The Sector-Specific Agencies work in voluntary cooperation with industry representatives to apply the Risk Management Framework and document results in corresponding Sector-Specific Plans. The program began in 2007 and the most recent Sector-Specific Plans were published in 2016. In February 2013, President Obama issued Executive 13636 directing the National Institute of Standards and Technology to develop a voluntary set of recommendations for strengthening infrastructure cybersecurity measures. EO13636 also asked Federal agencies with regulating authority to make a recommendation whether the NIST Cybersecurity Framework should be made mandatory. The Environmental Protection Agency who is both the SSA and regulatory authority for the drinking water subsector recommended voluntary application of the NIST Cybersecurity Framework. The Department of Energy who is both the SSA and regulatory authority for the electricity subsector replied that it was already implementing the Electricity Subsector Cybersecurity Capability Maturity Model, which indeed was what the NIST Cybersecurity Framework was based on. The Department of Energy, though, recommended voluntary application of the ES-C2M2. This module will examine both the drinking water and electricity lifeline infrastructure subsectors, and elements and application of the NIST Cybersecurity Framework and ES-C2M2.