工信部就“關于加強工業互聯網平臺安全建設的建議”進行答復
為貫徹落實習近平總書記關于堅持和完善人民代表大會制度的重要思想、關于加強和改進人民政協工作的重要思想,工業和信息化部積極做好十三屆全國人大四次會議代表建議、全國政協十三屆四次會議提案的辦理工作,特別是結合黨史學習教育,切實為民辦實事、解難題,強化組織指導,創新溝通機制,努力將代表委員提出的有價值、高質量建議轉化為破解難題的政策措施,推動工業和信息化事業高質量發展。為深入宣傳工業和信息化部2021年全國兩會建議提案辦理工作成果,工業和信息化部政務新媒體“工信微報”特開設“復文選編”欄目,陸續編發部分建議提案復文案例。
對十三屆全國人大四次會議第9992號建議的答復
田(tian)立坤代(dai)表:
您提出(chu)的(de)關(guan)于加強(qiang)工業(ye)互聯網平臺安全(quan)建(jian)設的(de)建(jian)議(yi)收悉(xi),現答復如下:
當前,工(gong)業互(hu)聯網快速(su)發(fa)展,平(ping)臺(tai)(tai)數量(liang)顯著增(zeng)長,融合(he)應用日趨(qu)成熟。工(gong)業互(hu)聯網平(ping)臺(tai)(tai)作(zuo)為工(gong)業互(hu)聯網的中(zhong)樞,向上承(cheng)載應用生態(tai),向下接(jie)入海(hai)量(liang)設備,面臨的網絡安全(quan)(quan)風險挑戰與(yu)日俱增(zeng)。我部贊同(tong)您提出的健全(quan)(quan)平(ping)臺(tai)(tai)安全(quan)(quan)管(guan)(guan)理體系、提升平(ping)臺(tai)(tai)安全(quan)(quan)技術防護能力、實施(shi)平(ping)臺(tai)(tai)數據(ju)安全(quan)(quan)分類(lei)分級管(guan)(guan)理、加強安全(quan)(quan)檢查評估等建議,將積極納入相關工(gong)作(zuo)舉(ju)措。
一、已開展工作
(一)推動(dong)構建工(gong)業(ye)(ye)互(hu)聯(lian)(lian)(lian)(lian)網(wang)(wang)(wang)(wang)平(ping)臺安(an)(an)(an)全(quan)(quan)(quan)(quan)政策(ce)體系。一是根(gen)據《國務院關(guan)于深化(hua)“互(hu)聯(lian)(lian)(lian)(lian)網(wang)(wang)(wang)(wang)+先進制(zhi)造業(ye)(ye)”發(fa)展(zhan)工(gong)業(ye)(ye)互(hu)聯(lian)(lian)(lian)(lian)網(wang)(wang)(wang)(wang)的(de)(de)(de)指(zhi)導意見》《加強工(gong)業(ye)(ye)互(hu)聯(lian)(lian)(lian)(lian)網(wang)(wang)(wang)(wang)安(an)(an)(an)全(quan)(quan)(quan)(quan)工(gong)作的(de)(de)(de)指(zhi)導意見》等文件要求(qiu),推動(dong)構建多部(bu)門協(xie)同推進、政府監(jian)管(guan)、企業(ye)(ye)主責的(de)(de)(de)安(an)(an)(an)全(quan)(quan)(quan)(quan)管(guan)理格(ge)局(ju),明確由(you)各地通信(xin)管(guan)理局(ju)加強工(gong)業(ye)(ye)互(hu)聯(lian)(lian)(lian)(lian)網(wang)(wang)(wang)(wang)平(ping)臺安(an)(an)(an)全(quan)(quan)(quan)(quan)監(jian)管(guan),并對(dui)聯(lian)(lian)(lian)(lian)網(wang)(wang)(wang)(wang)設(she)備(bei)、系統進行安(an)(an)(an)全(quan)(quan)(quan)(quan)監(jian)測。二是印發(fa)《關(guan)于開展(zhan)工(gong)業(ye)(ye)互(hu)聯(lian)(lian)(lian)(lian)網(wang)(wang)(wang)(wang)企業(ye)(ye)網(wang)(wang)(wang)(wang)絡安(an)(an)(an)全(quan)(quan)(quan)(quan)分(fen)類(lei)分(fen)級(ji)管(guan)理試點工(gong)作的(de)(de)(de)通知》,部(bu)署啟動(dong)分(fen)類(lei)分(fen)級(ji)管(guan)理試點工(gong)作,分(fen)類(lei)施策(ce)、分(fen)級(ji)防(fang)護,進一步加強平(ping)臺企業(ye)(ye)網(wang)(wang)(wang)(wang)絡安(an)(an)(an)全(quan)(quan)(quan)(quan)管(guan)理。三是推動(dong)《工(gong)業(ye)(ye)互(hu)聯(lian)(lian)(lian)(lian)網(wang)(wang)(wang)(wang)平(ping)臺企業(ye)(ye)網(wang)(wang)(wang)(wang)絡安(an)(an)(an)全(quan)(quan)(quan)(quan)防(fang)護規(gui)范》《工(gong)業(ye)(ye)互(hu)聯(lian)(lian)(lian)(lian)網(wang)(wang)(wang)(wang)數據安(an)(an)(an)全(quan)(quan)(quan)(quan)防(fang)護規(gui)范》等四項國家標(biao)準(zhun)立(li)項,加快研制(zhi)工(gong)業(ye)(ye)互(hu)聯(lian)(lian)(lian)(lian)網(wang)(wang)(wang)(wang)平(ping)臺安(an)(an)(an)全(quan)(quan)(quan)(quan)防(fang)護、安(an)(an)(an)全(quan)(quan)(quan)(quan)評(ping)估、安(an)(an)(an)全(quan)(quan)(quan)(quan)測試等30余(yu)項行業(ye)(ye)標(biao)準(zhun)。
(二)強(qiang)化工(gong)(gong)業(ye)(ye)互(hu)(hu)聯(lian)網(wang)(wang)平(ping)(ping)(ping)(ping)(ping)臺(tai)安(an)(an)全(quan)(quan)(quan)防(fang)護。一是(shi)依(yi)托工(gong)(gong)業(ye)(ye)互(hu)(hu)聯(lian)網(wang)(wang)創新發展工(gong)(gong)程,支持海爾、富士康等工(gong)(gong)業(ye)(ye)互(hu)(hu)聯(lian)網(wang)(wang)平(ping)(ping)(ping)(ping)(ping)臺(tai)企(qi)業(ye)(ye)建(jian)立安(an)(an)全(quan)(quan)(quan)接入(ru)、態勢(shi)感知、風(feng)險預警等技(ji)術手(shou)段,建(jian)成測(ce)(ce)試驗證、安(an)(an)全(quan)(quan)(quan)眾測(ce)(ce)等多(duo)個公(gong)共服(fu)務(wu)平(ping)(ping)(ping)(ping)(ping)臺(tai),鼓(gu)勵威脅誘捕、工(gong)(gong)業(ye)(ye)APP安(an)(an)全(quan)(quan)(quan)檢(jian)測(ce)(ce)等安(an)(an)全(quan)(quan)(quan)技(ji)術產(chan)品(pin)加快突破。二是(shi)依(yi)托國家(jia)工(gong)(gong)業(ye)(ye)互(hu)(hu)聯(lian)網(wang)(wang)安(an)(an)全(quan)(quan)(quan)技(ji)術監測(ce)(ce)服(fu)務(wu)平(ping)(ping)(ping)(ping)(ping)臺(tai),累計覆(fu)蓋重點(dian)工(gong)(gong)業(ye)(ye)互(hu)(hu)聯(lian)網(wang)(wang)平(ping)(ping)(ping)(ping)(ping)臺(tai)百余個,持續監測(ce)(ce)和處置惡意網(wang)(wang)絡行(xing)為。三是(shi)持續開展網(wang)(wang)絡安(an)(an)全(quan)(quan)(quan)技(ji)術應用試點(dian)示范,圍繞邊緣層(ceng)、基(ji)礎設(she)施層(ceng)(云IaaS)、平(ping)(ping)(ping)(ping)(ping)臺(tai)層(ceng)(工(gong)(gong)業(ye)(ye)PaaS)、應用層(ceng)(工(gong)(gong)業(ye)(ye)SaaS)以(yi)及(ji)工(gong)(gong)業(ye)(ye)APP等安(an)(an)全(quan)(quan)(quan)防(fang)護需求(qiu),遴(lin)選平(ping)(ping)(ping)(ping)(ping)臺(tai)安(an)(an)全(quan)(quan)(quan)防(fang)護優秀(xiu)解(jie)決方案,不斷加強(qiang)平(ping)(ping)(ping)(ping)(ping)臺(tai)安(an)(an)全(quan)(quan)(quan)防(fang)護能力建(jian)設(she)。
(三(san))扎實推(tui)進行業(ye)(ye)數(shu)(shu)據(ju)(ju)(ju)安(an)(an)全(quan)(quan)(quan)管理工(gong)(gong)作(zuo)。一是堅(jian)持法(fa)律法(fa)規(gui)制度先行,積極參與《數(shu)(shu)據(ju)(ju)(ju)安(an)(an)全(quan)(quan)(quan)法(fa)》等(deng)法(fa)律制定工(gong)(gong)作(zuo),夯實數(shu)(shu)據(ju)(ju)(ju)安(an)(an)全(quan)(quan)(quan)工(gong)(gong)作(zuo)法(fa)律基(ji)礎。二是印發《電(dian)信(xin)和互聯網(wang)(wang)行業(ye)(ye)數(shu)(shu)據(ju)(ju)(ju)安(an)(an)全(quan)(quan)(quan)標準體系建設(she)指(zhi)(zhi)南》等(deng)文件,研究發布行業(ye)(ye)網(wang)(wang)絡數(shu)(shu)據(ju)(ju)(ju)分類分級(ji)、重(zhong)(zhong)要數(shu)(shu)據(ju)(ju)(ju)識別等(deng)40余項重(zhong)(zhong)點(dian)行業(ye)(ye)標準。三(san)是部署開展(zhan)行業(ye)(ye)網(wang)(wang)絡數(shu)(shu)據(ju)(ju)(ju)安(an)(an)全(quan)(quan)(quan)保(bao)護能力(li)提升專(zhuan)項行動,印發《電(dian)信(xin)和互聯網(wang)(wang)企業(ye)(ye)網(wang)(wang)絡數(shu)(shu)據(ju)(ju)(ju)安(an)(an)全(quan)(quan)(quan)合規(gui)性評(ping)估(gu)(gu)要點(dian)(2020年)》,明(ming)確(que)合規(gui)評(ping)估(gu)(gu)指(zhi)(zhi)引。組織基(ji)礎電(dian)信(xin)企業(ye)(ye)開展(zhan)數(shu)(shu)據(ju)(ju)(ju)分類分級(ji)、重(zhong)(zhong)要數(shu)(shu)據(ju)(ju)(ju)識別、數(shu)(shu)據(ju)(ju)(ju)安(an)(an)全(quan)(quan)(quan)評(ping)估(gu)(gu)等(deng)標準貫標,指(zhi)(zhi)導重(zhong)(zhong)點(dian)互聯網(wang)(wang)企業(ye)(ye)開展(zhan)數(shu)(shu)據(ju)(ju)(ju)安(an)(an)全(quan)(quan)(quan)治理能力(li)評(ping)估(gu)(gu)。
(四(si))加快建設工(gong)業(ye)互聯(lian)(lian)網(wang)安(an)(an)(an)全(quan)技術防護(hu)體系。一是基本建成(cheng)國家(jia)、省、企業(ye)三級協同工(gong)業(ye)互聯(lian)(lian)網(wang)安(an)(an)(an)全(quan)技術監測(ce)服務體系,國家(jia)平(ping)臺已覆蓋汽車、電子、鋼鐵等14個(ge)重要行業(ye)領域,涉及工(gong)業(ye)企業(ye)10萬(wan)余家(jia)。二是組(zu)織開展(zhan)工(gong)業(ye)互聯(lian)(lian)網(wang)安(an)(an)(an)全(quan)檢查,開發檢測(ce)工(gong)具箱和驗證平(ping)臺,及時發現、通報(bao)和整(zheng)改安(an)(an)(an)全(quan)風險隱患近2000個(ge)。三是依托(tuo)工(gong)業(ye)互聯(lian)(lian)網(wang)企業(ye)網(wang)絡安(an)(an)(an)全(quan)分(fen)類分(fen)級管理試點(dian),面向平(ping)臺企業(ye)開展(zhan)檢測(ce)評估,指導平(ping)臺企業(ye)有效落(luo)實網(wang)絡安(an)(an)(an)全(quan)防護(hu)措施。
二、下一步工作考慮
做好平(ping)臺安(an)全保障對提(ti)升工業互聯網高(gao)質量發展水平(ping)具有重要(yao)意義。下一(yi)步,我部將圍繞健全平(ping)臺安(an)全管理(li)體系、提(ti)升平(ping)臺安(an)全防(fang)護能力、強化(hua)平(ping)臺數據安(an)全保護等方面著力做好以(yi)下有關工作:
(一)健全(quan)完善工(gong)(gong)業(ye)(ye)(ye)(ye)互聯網(wang)(wang)平(ping)臺安(an)全(quan)管(guan)理體系。一是推(tui)動出臺工(gong)(gong)業(ye)(ye)(ye)(ye)互聯網(wang)(wang)企(qi)業(ye)(ye)(ye)(ye)網(wang)(wang)絡安(an)全(quan)分(fen)(fen)類(lei)分(fen)(fen)級(ji)管(guan)理指(zhi)南,深入實施(shi)平(ping)臺企(qi)業(ye)(ye)(ye)(ye)網(wang)(wang)絡安(an)全(quan)分(fen)(fen)類(lei)分(fen)(fen)級(ji)管(guan)理,強(qiang)化(hua)重點平(ping)臺企(qi)業(ye)(ye)(ye)(ye)網(wang)(wang)絡安(an)全(quan)管(guan)理。二是推(tui)動印發《工(gong)(gong)業(ye)(ye)(ye)(ye)互聯網(wang)(wang)綜(zong)合標(biao)準化(hua)體系建設指(zhi)南》(2021版(ban)),加快工(gong)(gong)業(ye)(ye)(ye)(ye)互聯網(wang)(wang)平(ping)臺安(an)全(quan)分(fen)(fen)類(lei)分(fen)(fen)級(ji)管(guan)理等系列國家標(biao)準研制發布(bu),指(zhi)導企(qi)業(ye)(ye)(ye)(ye)落實網(wang)(wang)絡安(an)全(quan)主(zhu)體責任。
(二)持續提升(sheng)工業(ye)(ye)互聯(lian)網平(ping)臺(tai)(tai)安(an)(an)全(quan)(quan)(quan)防(fang)護水平(ping)。一(yi)(yi)是鼓勵重點平(ping)臺(tai)(tai)企(qi)業(ye)(ye)建設(she)企(qi)業(ye)(ye)級安(an)(an)全(quan)(quan)(quan)態勢感知能力(li),將(jiang)重點平(ping)臺(tai)(tai)納(na)入(ru)安(an)(an)全(quan)(quan)(quan)監測(ce)體系,加強平(ping)臺(tai)(tai)安(an)(an)全(quan)(quan)(quan)監測(ce)預警、應急處置。二是出臺(tai)(tai)中小企(qi)業(ye)(ye)安(an)(an)全(quan)(quan)(quan)上(shang)云上(shang)平(ping)臺(tai)(tai)政策措施,實(shi)施中小企(qi)業(ye)(ye)安(an)(an)全(quan)(quan)(quan)上(shang)云專項行動,為中小企(qi)業(ye)(ye)上(shang)云全(quan)(quan)(quan)流程提供(gong)安(an)(an)全(quan)(quan)(quan)指引。三是依托(tuo)工程項目、試點示范等,進一(yi)(yi)步加大平(ping)臺(tai)(tai)安(an)(an)全(quan)(quan)(quan)關(guan)鍵(jian)技術攻關(guan)和優秀項目遴選,促進網絡安(an)(an)全(quan)(quan)(quan)技術創新應用,提升(sheng)平(ping)臺(tai)(tai)安(an)(an)全(quan)(quan)(quan)保障和服務能力(li)。
(三)切實(shi)開(kai)展工(gong)業(ye)(ye)(ye)互聯(lian)網數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)全(quan)(quan)保(bao)護(hu)。一(yi)是(shi)(shi)落實(shi)《數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)全(quan)(quan)法》,研究制定工(gong)業(ye)(ye)(ye)互聯(lian)網數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)全(quan)(quan)管理政策(ce)文件,建立健(jian)全(quan)(quan)數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)分類(lei)分級(ji)保(bao)護(hu)、重要數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)保(bao)護(hu)等基礎制度。二是(shi)(shi)加快制定工(gong)業(ye)(ye)(ye)互聯(lian)網等重點(dian)領域數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)全(quan)(quan)標(biao)準(zhun)規范(fan),組織開(kai)展標(biao)準(zhun)驗證(zheng)和試點(dian)示范(fan),指導企(qi)業(ye)(ye)(ye)做(zuo)好數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)全(quan)(quan)保(bao)護(hu)工(gong)作(zuo)。三是(shi)(shi)大(da)力發展數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)全(quan)(quan)技(ji)術(shu)和產業(ye)(ye)(ye),鼓勵相關(guan)企(qi)業(ye)(ye)(ye)、研究機(ji)構積極參與數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)可信采(cai)集、數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)全(quan)(quan)態勢感(gan)知、數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)溯源等數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)全(quan)(quan)關(guan)鍵(jian)技(ji)術(shu)研發創新和應用推廣。四是(shi)(shi)組織研究數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)全(quan)(quan)保(bao)護(hu)認證(zheng)體系,制定行業(ye)(ye)(ye)數(shu)(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)全(quan)(quan)保(bao)護(hu)能(neng)力評(ping)估規范(fan),建立產學研共同參與的評(ping)估認證(zheng)機(ji)制,開(kai)展認證(zheng)工(gong)作(zuo)。
(四(si))系統(tong)強(qiang)化(hua)(hua)工(gong)業(ye)互聯(lian)網安(an)全(quan)保障能力。一是(shi)(shi)完善(shan)安(an)全(quan)技術監(jian)(jian)測(ce)(ce)服務體系,擴大(da)監(jian)(jian)測(ce)(ce)范(fan)圍,豐富平臺功能,提升監(jian)(jian)測(ce)(ce)質量(liang),提高支撐政府(fu)決策、保障企(qi)業(ye)安(an)全(quan)的(de)能力。二是(shi)(shi)充(chong)分發揮行業(ye)威(wei)脅信(xin)息共享平臺作用,推動(dong)建立跨(kua)地區(qu)、跨(kua)行業(ye)通報(bao)處置和應急聯(lian)動(dong)機制(zhi)(zhi),增強(qiang)工(gong)業(ye)互聯(lian)網重大(da)安(an)全(quan)風險、重大(da)安(an)全(quan)事件(jian)應對(dui)能力。三是(shi)(shi)健全(quan)安(an)全(quan)檢(jian)查檢(jian)測(ce)(ce)機制(zhi)(zhi),定期對(dui)重點平臺、工(gong)業(ye)企(qi)業(ye)、工(gong)業(ye)APP開展檢(jian)測(ce)(ce)評(ping)估,推動(dong)安(an)全(quan)檢(jian)測(ce)(ce)評(ping)估工(gong)作規范(fan)化(hua)(hua)、常態(tai)化(hua)(hua)、體系化(hua)(hua)。
感謝您(nin)對工業互聯網安全工作的關心(xin)和支持。
工業和信息化(hua)部
2021年9月14日
(來源:工(gong)信微報)