2016年,全球工业控制信息安全总体风险不断升温,工业控制系统相关漏洞数量居高不下,工业控制信息安全事件影响范围持续扩大。在工业控制系统的开放化、互联化为工业生产活动带来很多机会的同时,工业控制系统信息安全问题也日益凸显。2015年底至2016年底,乌克兰电网被攻击、全球第一款PLC蠕虫病毒的发现、北美遭受DDoS攻击造成大面积断网等一系列事件表明,工控安全形势依然严峻,工控安全已成为全球关注焦点。在这种背景下,美国等发达国家极为重视工控安全问题,在已有的标准、法规、政策的基础上,建立工控安全信息通报与共享机制,开展工控安全应急演练。我国也发布了《工业控制系统信息安全防护指南》和一系列的工控安全标准。
In 2016,the overall risks of global industry control system information security keep on rising,the relevant vulnerabilities of that stay at a high level,the scope of that information security event continues extending. With the opening and intercomnecting of ICS,which brings a lot of opportunities to industrial production,ICS information security incidents are increasingy prominent. In the period of 2015 to 2016,Ukraine power grid was attacked,the PLC worm was found for the first time,and north America suffered a network crash in large scale due to DDoS attack. These signs telling a grave situation of ICS security. More and more countries are sparing,no effort to enhance the ICS information security. Particularly,America and other developed countries are extremely mindful of it,that they have established the mechanism of ICS security information reporting,sharing upon the foundation of present standards,regulations and policies,and they also conduct emergency drilling. China published the “Guide on ICS Information Security Protection” and a series of standards for ICS information security,which have become a global focus.