Revision as of 14:39, 28 November 2024 editBobrayner (talk | contribs)Autopatrolled, Extended confirmed users, Pending changes reviewers, Rollbackers53,706 edits New: Cyber Security Management System. I'll expand it a bit more... | Revision as of 18:51, 28 November 2024 edit undoIdoghor Melody (talk | contribs)Autopatrolled, Event coordinators, Extended confirmed users, Page movers, IP block exemptions, New page reviewers, Pending changes reviewers32,104 editsm clean up, added Empty section (1) tag, typo(s) fixed: the the → theTag: AWBNext edit → | ||
Line 1: | Line 1: | ||
A '''Cyber Security Management System''' is a form of ], particularly focussed on protecting automation and transport systems.<ref>https://www.msg-plaut.com/cybersecurity/cyber-security-management-systems-csms</ref> |
A '''Cyber Security Management System''' is a form of ], particularly focussed on protecting automation and transport systems.<ref>https://www.msg-plaut.com/cybersecurity/cyber-security-management-systems-csms</ref> The EU Cybersecurity Act, of 2019, led to the creation of ] working groups which developed the Cyber Security Management Systems (CSMS) concept (and also an approach for securing over-the-air updates of vehicle systems), which were formalised in ].<ref>https://unece.org/sustainable-development/press/un-regulations-cybersecurity-and-software-updates-pave-way-mass-roll</ref> | ||
==Context== | ==Context== | ||
Security technologies, and threats, can evolve much more quickly than regulatory bodies; so |
Security technologies, and threats, can evolve much more quickly than regulatory bodies; so the CSMS emphasises a system of technologies and processes which can adapt more quickly, without relying on a narrowly-defined list of technical controls in a standard.<ref>https://plaxidityx.com/blog/standards-and-compliance/unece-recommendation-on-software-update-processes/</ref> Consequently, the CSMS is intended to be technology-neutral, much like ], unlike detailed technical security standards such as ]. | ||
==Framework== | ==Framework== | ||
{{Empty section|date=November 2024}} | |||
==See also== | ==See also== | ||
Line 13: | Line 13: | ||
* ] | * ] | ||
* ] | * ] | ||
==References== | ==References== | ||
{{reflist}} | {{reflist}} | ||
==Further |
==Further reading== | ||
* | * | ||
Revision as of 18:51, 28 November 2024
A Cyber Security Management System is a form of Information security management system, particularly focussed on protecting automation and transport systems. The EU Cybersecurity Act, of 2019, led to the creation of UNECE working groups which developed the Cyber Security Management Systems (CSMS) concept (and also an approach for securing over-the-air updates of vehicle systems), which were formalised in UN Regulation 155.
Context
Security technologies, and threats, can evolve much more quickly than regulatory bodies; so the CSMS emphasises a system of technologies and processes which can adapt more quickly, without relying on a narrowly-defined list of technical controls in a standard. Consequently, the CSMS is intended to be technology-neutral, much like ISO 27001, unlike detailed technical security standards such as PCI DSS.
Framework
This section is empty. You can help by adding to it. (November 2024) |
See also
References
- https://www.msg-plaut.com/cybersecurity/cyber-security-management-systems-csms
- https://unece.org/sustainable-development/press/un-regulations-cybersecurity-and-software-updates-pave-way-mass-roll
- https://plaxidityx.com/blog/standards-and-compliance/unece-recommendation-on-software-update-processes/