2020-09-06 智邦网
编译 致远
据c4isr网9月4日报道
9月4日,美白宫宣布,美国家太空委员会发布《空间政策指令-5》(SPD-5),颁布新的网络安全政策和原则,促进政府与商业空间业务运营,加强太空系统网络安全防卫。美国总统助理帮办兼国家航天委员会执行秘书斯科特·帕克说:“该政策和原则明确了保护空间资产和关键基础设施的政府综合框架体系”,作为“国家安全战略”和“国家网络战略”的具体实施,该政策旨在确保太空行动自由,保持美国领先地位。
SPD-5明确了太空系统网络安全原则:
- 太空系统及其支持基础设施包括软件,将采用基于风险的网络安全信息工程开发和运营;
- 太空系统运营商应为太空系统编制或充实网络安全规划,包括防止未经授权的访问、减少指挥控制和遥测系统漏洞、防止通信干扰和欺骗、应对地面系统的网络威胁、鼓励采用网络安全卫生做法、供应链风险管理;
- 太空系统网络安全需求及法规应广泛采纳最佳实践和行为规范;
- 太空系统空间系统使用者和运营商应密切合作,鼓励采用最佳做法和防卫方法;
- 太空系统操作员在满足系统网络安全要求时,应采取适当风险规避措施。
White House issues new cybersecurity policy for space systems
WASHINGTON — The National Space Council issued new cybersecurity principles to help defend America’s space systems Sept. 4. According to the White House, Space Policy Directive-5, or SPD-5, will foster practices within the government and commercial space operations to protect space systems from cyberthreats.
“From communications to weather monitoring, Americans rely on capabilities provided by space systems in everyday life. President [Donald] Trump’s directive ensures the U.S. Government promotes practices to protect American space systems and capabilities from cyber vulnerabilities and malicious threats,” Deputy Assistant to the President and Executive Secretary of the National Space Council Scott Pac said in a statement.
“Through establishing cybersecurity principles for space systems, Space Policy Directive-5 provides a whole-of-government framework to safeguard space assets and critical infrastructure.”
As a continuation of the National Security Strategy and National Cyber Strategy, the policy is intended to ensure freedom of action in space and maintain American leadership in the domain, the Trump administration said.
“Cyber security does not stop at America’s terrestrial borders,” added national security advisor Robert O’Brien. “The Administration is committed to protecting the American people from all cyber related threats to critical infrastructure, public health and safety, and our economic and national security — including American space systems and capabilities.”
SPD-5 lays out the following cybersecurity principles for space systems:
- Space systems and their supporting infrastructure, including software, should be developed and operated using risk-based, cybersecurity-informed engineering.
- Space systems operators should develop or integrate cybersecurity plans for space systems that include capabilities to protect against unauthorized access; reduce vulnerabilities of command, control and telemetry systems; protect against communications jamming and spoofing; protect ground systems from cyberthreats; promote adoption of appropriate cybersecurity hygiene practices; and manage supply chain risks.
- Space system cybersecurity requirements and regulations should leverage widely adopted best practices and norms of behavior.
- Space system owners and operators should collaborate to promote the development of best practices and mitigation approaches.
- Space system operators should make appropriate risk trades when implementing cybersecurity requirements specific to their system.