Centralized security governance for air navigation services: Innovative strategies to confront emerging threats against Civil Aviation

F. Maio
{"title":"Centralized security governance for air navigation services: Innovative strategies to confront emerging threats against Civil Aviation","authors":"F. Maio","doi":"10.1109/CCST.2014.6986968","DOIUrl":null,"url":null,"abstract":"Civil aviation remains an attracting target for criminals and the obligation to protect civil aviation against acts of unlawful interference must cope with increasingly sophisticated threats, many of a technological nature. The development of complex systems, by their nature interoperable, in an increasingly global and supranational environment, requires a methodological approach of the security governance to enable the constant monitoring of resources, process integration between IT, logical and physical security, continuously measuring the threat level and the potential vulnerability, with the aim to react and respond to acts of unlawful interference. This requires also a close and continuous link between all the actors of the system. The legal framework, both European and national, forms a solid term of reference, but the mere compliance with regulations is not enough, while it is always necessary to demonstrate due diligence for the protection of human lives in the air and on the ground and to ensure, in general, security, continuity, resilience and regularity of the public service of transportation by air. ENAV, Italian State-owned Air Navigation Service Provider, is in charge a vital segment of aviation and it has established an integrated security management system, focused on the concept of centralized government. Its centerpiece is the Security Operation Center, now evolving into an Integrated Defense Center, in constant evolution and aimed at a full context awareness and adaptive response. In accordance with Annex 17 to the Chicago Convention and related guidance material, ENAV provided a strategy based on the principle to combine technology, human and material resources, a set of processes and procedures intended to address a continuous improvement based on Deming cycle. Furthermore, the process management is focused on internationally recognized standards and committed to the exchange of information with the appropriate authorities and key stakeholders to achieve the dynamic configuration of the devices of physical and logical security and their responsiveness in the context of the system of critical infrastructure protection and cyber security system of the Italian Republic.","PeriodicalId":368721,"journal":{"name":"2014 International Carnahan Conference on Security Technology (ICCST)","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-12-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 International Carnahan Conference on Security Technology (ICCST)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CCST.2014.6986968","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Civil aviation remains an attracting target for criminals and the obligation to protect civil aviation against acts of unlawful interference must cope with increasingly sophisticated threats, many of a technological nature. The development of complex systems, by their nature interoperable, in an increasingly global and supranational environment, requires a methodological approach of the security governance to enable the constant monitoring of resources, process integration between IT, logical and physical security, continuously measuring the threat level and the potential vulnerability, with the aim to react and respond to acts of unlawful interference. This requires also a close and continuous link between all the actors of the system. The legal framework, both European and national, forms a solid term of reference, but the mere compliance with regulations is not enough, while it is always necessary to demonstrate due diligence for the protection of human lives in the air and on the ground and to ensure, in general, security, continuity, resilience and regularity of the public service of transportation by air. ENAV, Italian State-owned Air Navigation Service Provider, is in charge a vital segment of aviation and it has established an integrated security management system, focused on the concept of centralized government. Its centerpiece is the Security Operation Center, now evolving into an Integrated Defense Center, in constant evolution and aimed at a full context awareness and adaptive response. In accordance with Annex 17 to the Chicago Convention and related guidance material, ENAV provided a strategy based on the principle to combine technology, human and material resources, a set of processes and procedures intended to address a continuous improvement based on Deming cycle. Furthermore, the process management is focused on internationally recognized standards and committed to the exchange of information with the appropriate authorities and key stakeholders to achieve the dynamic configuration of the devices of physical and logical security and their responsiveness in the context of the system of critical infrastructure protection and cyber security system of the Italian Republic.
空中导航服务的集中安全治理:应对民用航空新出现的威胁的创新战略
民用航空仍然是吸引犯罪分子的目标,保护民用航空不受非法干扰的义务必须应对日益复杂的威胁,其中许多是技术性的威胁。在日益全球化和超国家的环境中,复杂系统的发展,由于其本质上是可互操作的,需要一种安全治理的方法学方法,以实现对资源的持续监控,IT、逻辑和物理安全之间的过程集成,持续测量威胁级别和潜在漏洞,目的是对非法干扰行为作出反应和响应。这也需要在系统的所有参与者之间建立密切和持续的联系。欧洲和各国的法律框架构成了坚实的职权范围,但仅仅遵守条例是不够的,同时始终有必要表现出应有的努力,以保护空中和地面上的人的生命,并在一般情况下确保公共航空运输服务的安全、连续性、弹性和规律性。ENAV是意大利国有空中导航服务提供商,负责航空的一个重要部分,它建立了一个综合安全管理系统,专注于中央政府的概念。它的核心是安全操作中心,现在正在演变成一个综合防御中心,不断发展,旨在实现全面的上下文感知和自适应响应。根据《芝加哥公约》附件17和相关指导材料,ENAV提供了基于技术、人力和物质资源相结合的原则的战略,一套旨在解决基于戴明循环的持续改进的过程和程序。此外,流程管理侧重于国际公认的标准,并致力于与有关当局和主要利益相关者交换信息,以实现物理和逻辑安全设备的动态配置及其在意大利共和国关键基础设施保护系统和网络安全系统背景下的响应能力。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信