本报告主要概述了车企在信息系统安全方面做应急响应的背景与风险、对象与目标、模式与方法以及相应的设计思路。在应急响应风险方面,主要分为网络安全的威胁——APT攻击、病毒泛滥以及安全漏洞等,法律法规要求和监管处罚风险以及数据保护不到位带来的风险。在网络安全应急响应的对象和目标方面,车企会根据业务所处阶段与类型的不同,分别设定相应的应急响应对象及目标。在制定应急响应模式时,大致可分为三个阶段:事前的分级、建立流程、指定负责人、做风险评估和应急演练阶段,事中的监控阶段,事后的处理与反馈阶段。具体的应急响应方案的设计思路需要如下考虑:安全事件分级设计、过程设计、工具设计、应急响应人员的培训与演练以及响应内容设计。同时,总结与展望了车企完成应急响应建设,提出车企应根据自身实际情况进行应急响应能力建设。
<<This section will mainly summarizes the background and risks,objects and targets,modes and methods of emergency response in information system security of automobile enterprises,as well as the corresponding design ideas. In terms of emergency response risks,they are mainly divided into network security threats:APT attacks,virus flooding,security vulnerabilities,etc.,legal and regulatory requirements and regulatory penalties,and risks caused by inadequate data protection. In terms of the objects and targets of network security emergency response,automobile companies will set the corresponding objects and targets of emergency response according to the different business stages and types. In the formulation of emergency response mode,it can be roughly divided into three stages:grading,establishing the process,appointing the person in charge,doing the risk assessment and emergency drill stage,monitoring stage and post-processing and feedback stage. Five aspects should be considered in the design of specific emergency response scheme:security incident grading design,process design,tool design,training and drill of emergency response personnel,and response content design. Finally,this section summarizes and looks forward to the completion of emergency response construction of automobile enterprises,and proposes that automobile enterprises should build emergency response capacity according to their actual situation. And the risks in cars are everywhere. This section only outlines the main ones.
<<