{"id":10971,"date":"2021-05-28T11:24:55","date_gmt":"2021-05-28T09:24:55","guid":{"rendered":"http:\/\/staging.blogs.yokogawa.de\/chemical-pharma\/uncategorized-tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/"},"modified":"2022-06-17T09:02:35","modified_gmt":"2022-06-17T07:02:35","slug":"risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim","status":"publish","type":"post","link":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/","title":{"rendered":"Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m"},"content":{"rendered":"<p>Bir senaryo d\u00fc\u015f\u00fcn\u00fcn ki; bir kimyasal i\u015fleme \u015firketi, \u00fcretim tesisi i\u00e7in siber g\u00fcvenlik program\u0131 ba\u015flatmaya karar verir, bu nedenle bir IT uzman\u0131 ile operasyon biriminden, tesis a\u011flar\u0131 hakk\u0131nda orta derece bilgi sahibi olan bir ki\u015fiyi bir araya getirir. Bu iki ki\u015finin ba\u015fka sorumluluklar\u0131 da vard\u0131r ve stratejik noktalara az say\u0131da g\u00fcvenlik cihaz\u0131n\u0131 h\u0131zl\u0131ca yerle\u015ftirerek bu yan sorumluluklar\u0131n\u0131 yerine getirdiklerini ve tesisin korundu\u011funu beyan ederler.<\/p>\n<p>Bu s\u0131rada, tesisin a\u011flar\u0131n\u0131 birka\u00e7 ayd\u0131r sistematik olarak analiz eden bir hacker, tesis mimarisini ve hangi varl\u0131klar\u0131n bulundu\u011funu tesisteki herkesten daha iyi bir \u015fekilde anlamaktad\u0131r. Hacker, birka\u00e7 y\u0131l \u00f6nce bir sistem entegrat\u00f6r\u00fcn\u00fcn kimyasal enjeksiyon problemini \u00e7\u00f6zmek i\u00e7in kurmu\u015f oldu\u011fu X marka PLC \u00fczerinden eri\u015fim sa\u011flam\u0131\u015ft\u0131r. Teknisyen, takip hizmeti i\u00e7in internet \u00fczerinden PLC&#8217;ye eri\u015fecek bir yol (path) b\u0131rakm\u0131\u015ft\u0131r, fakat herkes bunu unutmu\u015ftur. Hacker bu PLC&#8217;deki \u00f6nemli bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131n yani varsay\u0131lan parolan\u0131n &#8211; fark\u0131ndad\u0131r, \u00e7\u00fcnk\u00fc bunun \u00f6zellikleri yay\u0131nlanm\u0131\u015ft\u0131r, ancak tesis bu parolay\u0131 de\u011fi\u015ftirmek i\u00e7in asla bir ad\u0131m atmam\u0131\u015ft\u0131r, \u00e7\u00fcnk\u00fc bu parolan\u0131n varl\u0131\u011f\u0131n\u0131 bile unutmu\u015flard\u0131r. Bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131 hacker&#8217;a PLC&#8217;den otomasyon sistemine giden korunmas\u0131z bir ba\u011flant\u0131 yoluyla daha b\u00fcy\u00fck bir a\u011fa giden bir yol sa\u011flar.<\/p>\n<p>Bu senaryo fazla basitle\u015ftirilmi\u015f bir \u00f6rnek olsa da, operasyon teknolojisi (OT) a\u011flar\u0131na y\u00f6nelik siber g\u00fcvenlik stratejisine dair yakla\u015f\u0131mlar konusunda bir\u00e7ok \u015firketin kar\u015f\u0131la\u015ft\u0131\u011f\u0131 sorunlar\u0131 g\u00f6stermektedir. \u0130yi d\u00fc\u015f\u00fcn\u00fclm\u00fc\u015f bir strateji bu sorunlar\u0131 bulacak ve d\u00fczeltecektir, bu makalenin geri kalan\u0131nda bu t\u00fcr bir plan\u0131n nas\u0131l uygulanaca\u011f\u0131na bakaca\u011f\u0131z.<\/p>\n<h2><strong>De\u011fi\u015fen sald\u0131r\u0131 y\u00fczeyi<\/strong><\/h2>\n<p>IT ve OT&#8217;nin bir araya getirilmesi ve IT teknolojilerinin OT a\u011flar\u0131ndaki geni\u015flemesinin sald\u0131r\u0131 y\u00fczeyini nas\u0131l geli\u015ftirdi\u011fi, ayn\u0131 zamanda yeni savunma ara\u00e7lar\u0131n\u0131 da ortaya \u00e7\u0131kard\u0131\u011f\u0131 hakk\u0131nda bir\u00e7ok \u015fey yaz\u0131lm\u0131\u015ft\u0131r.<\/p>\n<p>Daha \u00f6nceleri tesisler tamamen izoleydi, ancak \u015fimdi \u015firket intranetleri ve\/veya internet ile, muhtemelen bir\u00e7ok ki\u015finin fark etti\u011finden daha fazla yollarla, d\u0131\u015f d\u00fcnya ile ba\u011flant\u0131 halindeler. \u015eirketler tesislerinde yaln\u0131zca dikey ba\u011flant\u0131 sa\u011flayarak de\u011fil, ayn\u0131 zamanda \u015fantiyelerinde, di\u011fer sahalar\u0131nda ve tedarik zinciri boyunca yatay ba\u011flant\u0131 sa\u011flayarak, operasyonlar\u0131n\u0131 ve i\u015flerini rekabet ad\u0131na dijital olarak d\u00f6n\u00fc\u015ft\u00fcrmeye \u00e7al\u0131\u015fmaktad\u0131rlar. Bu ba\u011flant\u0131lar i\u015f a\u00e7\u0131s\u0131ndan avantajlar yarat\u0131r, fakat a\u011f ve verilerin g\u00fcvenli\u011fini sa\u011flamada zorluklar da yarat\u0131r.<\/p>\n<p>B\u00fcy\u00fck operasyonlar\u0131 optimize etmek i\u00e7in gereken daha fazla bile\u015fen ve i\u015flev ile, tesislerin Windows, Ethernet ve TCP\/IP gibi ticari teknolojilerin kullan\u0131m\u0131yla giderek daha karma\u015f\u0131k ve otomatikle\u015ftirilmi\u015f bir h\u00e2le gelmektedir. Ara\u015ft\u0131rma, ilk \u00fc\u00e7 siber tehdidin a\u011fa eklenen cihazlar ve &#8220;sistemler&#8221; (a\u00e7\u0131l\u0131\u015f \u00f6rne\u011fimizdeki PLC gibi), i\u00e7 tehditler (insan ihmali veya kazalar\u0131) ve d\u0131\u015f tehditler (tedarik zinciri veya ortakl\u0131klar) oldu\u011funu g\u00f6stermektedir (\u015eekil 1).<\/p>\n<p style=\"text-align: center\"><strong><em><img decoding=\"async\" class=\" wp-image-15500 aligncenter\" src=\"https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/1-3-300x153.jpg\" alt=\"\" width=\"590\" height=\"301\" \/>\u015eekil 1: IT\/ICS Siber g\u00fcvenlik anketinde SANS enstit\u00fcs\u00fc taraf\u0131ndan derlenen, \u00f6nde gelen siber tehditlerin 2019 y\u0131l\u0131ndaki durumu<\/em><\/strong><\/p>\n<p style=\"text-align: center\"><strong>OT &#8216;nin de\u011fi\u015fime kar\u015f\u0131 do\u011fal direnci<\/strong><\/p>\n<p>OT a\u011flar\u0131ndan sorumlu olanlar her zaman IT b\u00f6l\u00fcm\u00fcnden yard\u0131m almazlar. E\u011fer bir \u015fey i\u015fe yar\u0131yorsa ve kesintisiz \u00fcretimin sa\u011flanmas\u0131 i\u00e7in gerekliyse, eski ve iyi korunmam\u0131\u015f olsa dahi genel cevap &#8220;Dokunma&#8221;d\u0131r. IT&#8217;nin tesise getirmek istedi\u011fi ara\u00e7lar ve daha \u00fcst s\u00fcr\u00fcmler eski ekipman ve yaz\u0131l\u0131mlara uygun olmayabilir ve \u00fcretim kesintilerine hatta g\u00fcvenlik tehlikelerine sebep olabilir. \u00d6te yandan, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar da ayn\u0131 \u015feylere sebep olabilir, dolay\u0131s\u0131yla IT m\u00fcdahale etme ihtiyac\u0131 hisseder. Ancak, OT g\u00fcvenli\u011fini art\u0131rmak i\u00e7in IT g\u00fcvenlik teknolojisi ve politikalar\u0131n\u0131 OT ortam\u0131na aktarmak i\u015fe yaramaz, \u00e7\u00fcnk\u00fc IT g\u00fcvenli\u011fi farkl\u0131 gereksinimler ve \u00f6nceliklerle \u00e7al\u0131\u015f\u0131r.<\/p>\n<p>IT, end\u00fcstriyel kontrol sistemin, tesisin beyni oldu\u011funu anlamal\u0131d\u0131r. Sistemin emre amadeli\u011fi, dayan\u0131kl\u0131l\u0131\u011f\u0131 ve s\u00fcrd\u00fcr\u00fclebilirli\u011fi ayn\u0131 zamanda g\u00fcvenli\u011fi, operasyonel maliyeti ve i\u015f performans\u0131n\u0131 etkiler.Dolay\u0131s\u0131yla end\u00fcstriyel kontrol sisteminin performans\u0131na m\u00fcdahale eden her \u015fey \u015firketi, \u00fcst y\u00f6netimi ve payda\u015flar\u0131 etkiler.<\/p>\n<p>Bu durum \u0131\u015f\u0131\u011f\u0131nda, g\u00fcvenlik riski y\u00f6netimi, ciddi zorluklara ra\u011fmen kurulu\u015flar ve sorumlu ekipler i\u00e7in en \u00f6nemli \u00f6nceliktir:<\/p>\n<ul>\n<li>OT varl\u0131klar\u0131n\u0131n d\u00fc\u015f\u00fck g\u00f6r\u00fcn\u00fcrl\u00fck riskinin de\u011ferlendirilmesi \u2014 Tesisler y\u0131llar i\u00e7inde geli\u015fir ve a\u00e7\u0131l\u0131\u015f \u00f6rne\u011findeki PLC gibi, bir\u00e7o\u011fu de\u011fi\u015fiklikleri belgelemede iyi de\u011fildirler, potansiyel g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 aramak i\u00e7in altyap\u0131y\u0131 da derinlemesine incelemezler.<\/li>\n<li>Riskin azalt\u0131lmas\u0131 ve yat\u0131r\u0131m\u0131n \u00f6nceliklendirilmesi \u2014 \u015eirketler OT varl\u0131klar\u0131nda az g\u00f6r\u00fcn\u00fcrl\u00fc\u011fe sahipse, g\u00fcvenlik i\u00e7in ne kadar yat\u0131r\u0131m gerekti\u011finin veya \u00e7aban\u0131n nereden ba\u015flamas\u0131 gerekti\u011finin tahmin edilmesi zordur. Ayr\u0131ca, \u00e7aba ile bu riskin ne kadar azald\u0131\u011f\u0131n\u0131 bilmek de imk\u00e2ns\u0131z olacakt\u0131r.<\/li>\n<li>End\u00fcstri standartlar\u0131na ayak uydurmak \u2014 Tedbirlerin uygulanmas\u0131 ve geli\u015fen\/de\u011fi\u015fen standartlara uyum sa\u011flamaya devam etmek zorlay\u0131c\u0131 bir i\u015ftir. Bu konuyu birazdan daha ayr\u0131nt\u0131l\u0131 a\u00e7\u0131klayaca\u011f\u0131z.<\/li>\n<li>S\u0131n\u0131rl\u0131 OT g\u00fcvenli\u011fi uzmanl\u0131\u011f\u0131 ile risk y\u00f6netimi \u2014 G\u00fcvenlik \u00f6nlemlerinin uygulanmas\u0131n\u0131n ve y\u00f6netiminin, 20 y\u0131ldan uzun s\u00fcren tesis ya\u015fam d\u00f6ng\u00fcs\u00fc boyunca devam etmesi gerekirken, g\u00fcvenlik ekipleri genellikle g\u00fcvenlik personeli ve uzmanl\u0131k eksikli\u011fi ile kar\u015f\u0131 kar\u015f\u0131ya kalmaktad\u0131r.<\/li>\n<\/ul>\n<h3><strong>Risk tabanl\u0131 yakla\u015f\u0131m<\/strong><\/h3>\n<p>Riski azaltmaya y\u00f6nelik iki genel yakla\u015f\u0131m vard\u0131r. Olgunluk tabanl\u0131 yakla\u015f\u0131m, her \u015feyde en \u00fcst d\u00fczey savunma olu\u015fturur. En kapsaml\u0131 olan\u0131d\u0131r, ancak \u00e7ok pahal\u0131d\u0131r. Risk tabanl\u0131 yakla\u015f\u0131m, en \u00e7ok ihtiya\u00e7 duyuldu\u011fu zamanlarda risk azalt\u0131lmas\u0131na y\u00f6nelik savunma katmanlar\u0131n\u0131 optimize etmektedir. Bu baz\u0131 kapsamlardan fedak\u00e2rl\u0131k eder, ancak daha ucuzdur ve uygulanmas\u0131 daha kolayd\u0131r, b\u00f6ylece ger\u00e7ekle\u015fmesi daha olas\u0131d\u0131r.<\/p>\n<h3><strong>Risk tabanl\u0131 g\u00fcvenlik d\u00f6rt uygulamaya dayanmaktad\u0131r:<\/strong><\/h3>\n<ul>\n<li>G\u00fcvenlik temelinin (security baseline) belirlenmesi: \u0130lk ad\u0131m, risklerin tespit edilmesi ve OT g\u00fcvenlik payda\u015flar\u0131n\u0131n bu temeli anlamas\u0131n\u0131 sa\u011flamakt\u0131r. Tesisin mevcut durumuna hakim olmak g\u00fcvenlik yolculu\u011funun ba\u015flad\u0131\u011f\u0131 noktad\u0131r.<\/li>\n<li>Riskin b\u00fct\u00fcnsel bir bak\u0131\u015f a\u00e7\u0131s\u0131yla tan\u0131mlanmas\u0131: Riskler bir\u00e7ok fark\u0131 y\u00f6nden ve kategoriden gelir, dolay\u0131s\u0131yla yaln\u0131zca y\u00fcksek d\u00fczey i\u015f proseslerine odakl\u0131 bir risk de\u011ferlendirmesi, teknik uygulamalardaki kusurlar sebebiyle riskleri tespit edemeyebilir.<\/li>\n<li>G\u00fcvenlik standartlar\u0131na uyulmas\u0131: Her seferinde tekerle\u011fi yeniden icat etmeye k\u0131yasla, g\u00fcvenlik program\u0131n\u0131 daha etkili ve basit bir h\u00e2le getirdi\u011fi i\u00e7in, mevcut g\u00fcvenlik standard\u0131na uygunluk faydal\u0131d\u0131r.<\/li>\n<li>Sistematik bir proses olu\u015fturulmas\u0131: OT g\u00fcvenli\u011fine y\u00f6nelik kal\u0131c\u0131 bir operasyonel risk y\u00f6netimi olu\u015fturmak i\u00e7in kurulu\u015flar sistematik bir prosese uymal\u0131d\u0131r. Bu risk y\u00f6netimi s\u00fcreci, k\u0131sa ve uzun vadeli konular\u0131 i\u00e7eren stratejik bir faaliyettir. Bu nedenle, s\u00fcrekli risk g\u00fcvencesini sa\u011flamak i\u00e7in stratejik risk y\u00f6netimi planlamas\u0131 gereklidir.<\/li>\n<\/ul>\n<h3><strong>\u00a0G\u00fcvenlik standartlar\u0131<\/strong><\/h3>\n<p>Az \u00f6nce de belirtildi\u011fi gibi, riske dayal\u0131 g\u00fcvenli\u011fin \u00f6nemli bir unsuru ilgili standartlara uymakt\u0131r. \u00d6rne\u011fin peynir \u00fcretimi i\u00e7in kurulan bir tesis, kendi belirledi\u011fi temizlik tan\u0131mlar\u0131ndan ziyade y\u00fcr\u00fcrl\u00fckteki y\u00f6netmeliklere uymak zorundad\u0131r. Benzer \u015fekilde, siber g\u00fcvenlik, \u015firketlere yard\u0131mc\u0131 olmak i\u00e7in kendi uygulamalar\u0131na ve y\u00f6nergelerine sahiptir. Say\u0131lar\u0131 gitgide artan \u015firketler a\u015fa\u011f\u0131dakilere uygun \u015fekilde \u00e7al\u0131\u015fmaktad\u0131r:<\/p>\n<ul>\n<li>ISA\/IEC 62443<\/li>\n<li>NIST CSF<\/li>\n<li>NIST 800-82<\/li>\n<li>CIS Kritik G\u00fcvenlik Kontrolleri.<\/li>\n<li>ISO 27000 (Genellikle IT&#8217;de kullan\u0131l\u0131r)<\/li>\n<\/ul>\n<p>T\u00fcm y\u00f6nleri ve b\u00f6lgeleri kapsayan tek bir d\u00fczenleme, standart veya uygulama yoktur. Avrupa\u2019da, NIS (A\u011f ve Bilgi Sistemleri) Y\u00f6nergesi y\u00fcr\u00fcrl\u00fc\u011fe girmi\u015ftir ve her \u00fclke baz\u0131nda ge\u00e7erli kanun haline gelecektir.<\/p>\n<p>Muhtemelen, yukar\u0131daki listedeki en \u00f6nemli standart IEC 62443&#8217;t\u00fcr, \u00e7\u00fcnk\u00fc end\u00fcstriyel sistemler i\u00e7in \u00f6zel olarak tasarlanm\u0131\u015ft\u0131r ve risk de\u011ferlendirmesinden teknik tasar\u0131m \u00f6zelliklerine kadar bir g\u00fcvenlik program\u0131n\u0131n her y\u00f6n\u00fcn\u00fc kapsar. Yakla\u015f\u0131m\u0131, bir tesis veya bir tesisin b\u00f6lgeleri i\u00e7in hedef g\u00fcvenlik d\u00fczeyini tan\u0131mlamaktad\u0131r (\u015eekil 2). \u015eirketler, tesislerini de\u011ferlendirirken do\u011fru hedef g\u00fcvenlik d\u00fczeyini belirlemelidir.<\/p>\n<p style=\"text-align: center\"><strong><em><img decoding=\"async\" class=\" wp-image-15514 aligncenter\" src=\"https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/2-4-300x127.jpg\" alt=\"\" width=\"702\" height=\"297\" \/>\u015eekil 2: IEC 62443-3-3 &#8216;teki tan\u0131mlara dayal\u0131 g\u00fcvenlik d\u00fczeyleri<\/em><\/strong><\/p>\n<p>Ayr\u0131ca, emniyet\/acil duru\u015f sistemlerinin (SIS-Safety Instrumented System) olu\u015fturulmas\u0131na y\u00f6nelik uygulamalar\u0131 belirleyen teknik standart olan IEC 61511, g\u00fcvenlik risk de\u011ferlendirmelerinin yap\u0131lmas\u0131n\u0131n art\u0131k zorunlu bir gereksinim oldu\u011funu a\u00e7\u0131k\u00e7a belirtmektedir.<\/p>\n<h3><strong>\u0130lk ad\u0131m: Risk De\u011ferlendirmesi<\/strong><\/h3>\n<p>Risk tabanl\u0131 siber g\u00fcvenlik y\u00f6netiminin ilk ad\u0131m\u0131 olarak Yokogawa, OT g\u00fcvenlik temelini elde etmek i\u00e7in teknik g\u00fcvenlik risk de\u011ferlendirmesinin (TSRA) yap\u0131lmas\u0131n\u0131 \u00f6nermektedir. TSRA, OT ortam\u0131n\u0131n kar\u015f\u0131 kar\u015f\u0131ya kald\u0131\u011f\u0131 tehditlere ili\u015fkin etki ve olas\u0131l\u0131\u011f\u0131 de\u011ferlendirerek kurulu\u015fun g\u00fcvenlik riskini belirler.<\/p>\n<p>Yokogawa&#8217;n\u0131n TSRA s\u00fcreci, m\u00fc\u015fteri g\u00f6r\u00fc\u015fmelerine ve teknik incelemelere dayanan bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 de\u011ferlendirmesi ile ba\u015flar. G\u00fcvenlik a\u00e7\u0131klar\u0131 tespit edildi\u011finde, OT ortam\u0131n\u0131n kar\u015f\u0131 kar\u015f\u0131ya oldu\u011fu en y\u00fcksek riskleri ve hangi sorunlar\u0131n en acil \u015fekilde \u00e7\u00f6z\u00fclmesi gerekti\u011fini belirlemek i\u00e7in senaryo tabanl\u0131 bir risk de\u011ferlendirmesi yap\u0131l\u0131r. G\u00fcvenlik a\u00e7\u0131klar\u0131 ve riskler ayn\u0131 de\u011fildir (\u015eekil 3). Bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 bir kusur veya zay\u0131fl\u0131kken, risk ise k\u00f6t\u00fc bir \u015feyin olma olas\u0131l\u0131\u011f\u0131d\u0131r. A\u00e7\u0131l\u0131\u015f \u00f6rne\u011fine d\u00f6nersek, g\u00fcvenlik a\u00e7\u0131\u011f\u0131 varsay\u0131lan parolad\u0131r. Bir ba\u015fka tipik g\u00fcvenlik a\u00e7\u0131\u011f\u0131, belirlenmi\u015f s\u0131n\u0131r korumas\u0131n\u0131n olmamas\u0131 olabilir. Risk, bir hacker bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131ndan yararlan\u0131rsa ne olabilece\u011fidir.<\/p>\n<p style=\"text-align: center\"><strong><em><img decoding=\"async\" class=\" wp-image-15507 aligncenter\" src=\"https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/3-5-300x193.jpg\" alt=\"\" width=\"647\" height=\"416\" \/>\u015eekil 3: Her g\u00fcvenlik a\u00e7\u0131\u011f\u0131, k\u00f6t\u00fc niyetli olarak kullan\u0131labilme olas\u0131l\u0131\u011f\u0131 \u0131\u015f\u0131\u011f\u0131nda incelenmelidir.<\/em><\/strong><\/p>\n<p>Teknik g\u00fcvenlik a\u00e7\u0131\u011f\u0131 de\u011ferlendirme a\u015famas\u0131nda, g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 toplamak, bulgular\u0131 do\u011frulamak ve kontrol etmek, ortamda mevcut olan g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131n eksiksiz ve g\u00fcvenilir bir listesini olu\u015fturmak i\u00e7in birden fazla y\u00f6ntem kullan\u0131l\u0131r. Bu liste, g\u00fcvenlik a\u00e7\u0131\u011f\u0131 de\u011ferlendirme a\u015famas\u0131nda yer alan ayn\u0131 ekip taraf\u0131ndan y\u00fcr\u00fct\u00fclen risk de\u011ferlendirme a\u015famas\u0131n\u0131n giri\u015f k\u0131sm\u0131n\u0131 olu\u015fturur. Bu, risk de\u011ferlendirmesinin ba\u015flang\u0131c\u0131nda g\u00fcvenlik a\u00e7\u0131klar\u0131 ile ilgili b\u00fcy\u00fck miktarda bilgi ve i\u00e7 g\u00f6r\u00fcn\u00fcn mevcut olaca\u011f\u0131 anlam\u0131na gelir.<\/p>\n<h3><strong>Teknik risk de\u011ferlendirmesi, a\u015fa\u011f\u0131dakileri i\u00e7eren bir raporla sonu\u00e7lan\u0131r:<\/strong><\/h3>\n<ul>\n<li>Risklerin ve g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131n listesi<\/li>\n<li>Herhangi bir \u00fcst d\u00fczey risk ve gerekli acil \u00f6nlemler hakk\u0131nda bulgular;<\/li>\n<li>Tesisin mevcut durumu ile g\u00fcvenlik gereksinimleri aras\u0131nda bir bo\u015fluk analizi<\/li>\n<li>Tedbirler ve di\u011fer somut \u00f6neriler i\u00e7in planlar da dahil olmak \u00fczere g\u00fcvenlik program\u0131n\u0131n nas\u0131l iyile\u015ftirilece\u011fini veya geli\u015ftirilece\u011fini g\u00f6steren bir yol haritas\u0131.<\/li>\n<\/ul>\n<h3><strong>\u00a0De\u011ferlendirme metodolojisi<\/strong><\/h3>\n<p>Dan\u0131\u015fmanlar ve m\u00fchendisler, g\u00f6r\u00fc\u015fmeler ve teknik denetimler de dahil olmak \u00fczere \u00e7e\u015fitli y\u00f6ntemler kullanarak g\u00fcvenlik a\u00e7\u0131\u011f\u0131 de\u011ferlendirmesini birlikte ger\u00e7ekle\u015ftirirler.<\/p>\n<p>G\u00f6r\u00fc\u015fmeler, hem IEC 62443 hem de Yokogawa&#8217;n\u0131n g\u00fcvenlik deneyimine dayanan kapsaml\u0131 bir anket arac\u0131l\u0131\u011f\u0131yla ger\u00e7ekle\u015fir. Sorular, ayr\u0131nt\u0131l\u0131 teknik uygulamadan, g\u00fcvenli\u011fin yerel kurulu\u015f taraf\u0131ndan nas\u0131l y\u00f6netildi\u011fine kadar \u00e7e\u015fitlilik g\u00f6sterir. Bu sorulara verilen cevaplar, kullan\u0131c\u0131 ve PC y\u00f6netimi, a\u011f ayg\u0131t\u0131 envanteri, yamalar, g\u00fcncellemeler ve Anti vir\u00fcs y\u00f6netimi de dahil olmak \u00fczere teknik denetimlerle entegre edilir.<\/p>\n<p>Her g\u00fcvenlik a\u00e7\u0131\u011f\u0131, riski belirlemek i\u00e7in incelenmelidir; bu, bir hacker\u2019\u0131n g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131 kullanarak ne kadar zarar verebilece\u011fi ile, zarar verici bu eylemin ger\u00e7ekle\u015fme olas\u0131l\u0131\u011f\u0131n\u0131n kombinasyonudur. Etki ve olas\u0131l\u0131k kombinasyonu risk d\u00fczeyi haline gelir (\u015eekil 4).<\/p>\n<p style=\"text-align: center\"><strong><em><img decoding=\"async\" class=\" wp-image-15521 aligncenter\" src=\"https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4-300x202.jpg\" alt=\"\" width=\"698\" height=\"470\" \/>\u015eekil 4: T\u00fcm sald\u0131r\u0131 vekt\u00f6rleri ayn\u0131 de\u011fildir, bu nedenle savunma risk d\u00fczeyini yans\u0131tmal\u0131d\u0131r<\/em><\/strong><em>.<\/em><\/p>\n<h3>\u00a0G\u00fcvenlik a\u00e7\u0131\u011f\u0131 ve risk de\u011ferlendirmelerinin sonucu, a\u015fa\u011f\u0131dakileri i\u00e7eren TSRA raporunda belgelenir:<\/h3>\n<ul>\n<li>Y\u00f6netim \u00f6zeti<\/li>\n<li>Metodolojiye genel bak\u0131\u015f<\/li>\n<li>OT ortam\u0131 i\u00e7in risklere genel bak\u0131\u015f<\/li>\n<li>OT ortam\u0131 i\u00e7in g\u00fcvenlik a\u00e7\u0131\u011f\u0131na genel bak\u0131\u015f<\/li>\n<li>Tesisin mevcut durumu ve g\u00fcvenlik gereksinimleri aras\u0131ndaki bo\u015fluk analizi<\/li>\n<li>G\u00fcvenlik program\u0131n\u0131n nas\u0131l iyile\u015ftirilece\u011fine veya geli\u015ftirilece\u011fine dair yol haritas\u0131.<\/li>\n<\/ul>\n<p>De\u011ferlendirmenin sonucu, \u00fcst d\u00fczey riski ele almak i\u00e7in hangi acil \u00f6nlemlerin al\u0131nmas\u0131 gerekti\u011fi ve kar\u015f\u0131 \u00f6nlemlerin uygulanmas\u0131 i\u00e7in etkili bir g\u00fcvenlik program\u0131n\u0131n nas\u0131l planlanaca\u011f\u0131 konusunda y\u00f6netim ile yap\u0131c\u0131 tart\u0131\u015fmay\u0131 destekleyecektir. Nihai hedef, tehditler ve ara\u00e7lar geli\u015ftik\u00e7e s\u00fcrekli olarak de\u011ferlendirilen ve geli\u015ftirilen bir programa ula\u015fmakt\u0131r.<\/p>\n<p>Risk tabanl\u0131 bir yakla\u015f\u0131m\u0131n benimsenmesi, kurulu\u015flar\u0131n karma\u015f\u0131k kararlar almas\u0131na, hangi eylemin yap\u0131laca\u011f\u0131na ve nereye yat\u0131r\u0131m yap\u0131laca\u011f\u0131na dair yol g\u00f6sterecektir. Etkin risk y\u00f6netimi, \u015firkete ve tesise \u00f6zg\u00fc riskleri bilmek ve iyice anlamak ile ba\u015flar. Ancak, karma\u015f\u0131k operasyonel ortam, geli\u015fen siber tehditler ve s\u00fcrekli g\u00fcncellenen yasalar ve politikalar, kurulu\u015flar\u0131n bu sorumlulu\u011fu kurum i\u00e7inde ele almalar\u0131n\u0131 son derece zorla\u015ft\u0131rmaktad\u0131r.<\/p>\n<p>Bu, en deneyimli profesyoneller i\u00e7in bile zor olabilece\u011finden, bir\u00e7ok \u015firket g\u00fcvenlik de\u011ferlendirmeleri s\u00f6z konusu oldu\u011funda g\u00fcvenlik ortaklar\u0131ndan destek ister. Yokogawa&#8217;n\u0131n dan\u0131\u015fmanlar\u0131 ve m\u00fchendisleri hem tesis operasyonu hem de OT g\u00fcvenli\u011fi konusunda derinlemesine bilgiye ve geni\u015f deneyime sahip olarak, g\u00fcvenlik yolculu\u011fu boyunca rehber olarak hizmet sunabilirler.<\/p>\n<hr \/>\n<blockquote class=\"wp-embedded-content\" data-secret=\"PH7BdhAUep\"><p><a href=\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/otomasyon\/enerji-ve-emisyon-yonetimine-yonelik-gercek-zamanli-modele-dayali-dijital-ikiz\/\">Enerji ve Emisyon Y\u00f6netimine Y\u00f6nelik Ger\u00e7ek Zamanl\u0131, Modele Dayal\u0131 Dijital \u0130kiz<\/a><\/p><\/blockquote>\n<p><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;Enerji ve Emisyon Y\u00f6netimine Y\u00f6nelik Ger\u00e7ek Zamanl\u0131, Modele Dayal\u0131 Dijital \u0130kiz&#8221; &#8212; Chemical Pharma Blog\" src=\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/otomasyon\/enerji-ve-emisyon-yonetimine-yonelik-gercek-zamanli-modele-dayali-dijital-ikiz\/embed\/#?secret=bsAw3xSI7J#?secret=PH7BdhAUep\" data-secret=\"PH7BdhAUep\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Risk tabanl\u0131 Yokogawa siber g\u00fcvenlik y\u00f6netimi ile ilgili daha detayl\u0131 bilgi i\u00e7in makalemizi okuyabilirsiniz. <\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/\"> <span class=\"screen-reader-text\">Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m<\/span> Devam\u0131 &raquo;<\/a><\/p>\n","protected":false},"author":147,"featured_media":10986,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"","footnotes":""},"categories":[2067,2061],"tags":[2254,305,781,614,95,2255,2256,884,99,452,2257,74,2258],"coauthors":[886],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v20.13 (Yoast SEO v20.13) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m - Chemical Pharma Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/\" \/>\n<meta property=\"og:locale\" content=\"tr_TR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m\" \/>\n<meta property=\"og:description\" content=\"Risk tabanl\u0131 Yokogawa siber g\u00fcvenlik y\u00f6netimi ile ilgili daha detayl\u0131 bilgi i\u00e7in makalemizi okuyabilirsiniz.  Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m Devam\u0131 &raquo;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/\" \/>\n<meta property=\"og:site_name\" content=\"Chemical Pharma Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-28T09:24:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-06-17T07:02:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"901\" \/>\n\t<meta property=\"og:image:height\" content=\"608\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Yokogawa Turkey editorial team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/\"},\"author\":{\"name\":\"Yokogawa Turkey editorial team\",\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#\/schema\/person\/a1d9373fe7371d03437657ff780101fc\"},\"headline\":\"Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m\",\"datePublished\":\"2021-05-28T09:24:55+00:00\",\"dateModified\":\"2022-06-17T07:02:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/\"},\"wordCount\":2413,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#organization\"},\"keywords\":[\"CIS\",\"IEC\",\"ISA\",\"ISO\",\"IT\",\"ITS\",\"NIST 800\",\"NIST CSF\",\"OT\",\"PLC\",\"risk de\u011ferlendirmesi\",\"Security\",\"SIS-Safety Instrumented System\"],\"articleSection\":[\"Emniyet &amp; G\u00fcvenlik\",\"Optimizasyon\"],\"inLanguage\":\"tr\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/\",\"url\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/\",\"name\":\"Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m - Chemical Pharma Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#website\"},\"datePublished\":\"2021-05-28T09:24:55+00:00\",\"dateModified\":\"2022-06-17T07:02:35+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/#breadcrumb\"},\"inLanguage\":\"tr\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#website\",\"url\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/\",\"name\":\"Chemical Pharma Blog\",\"description\":\"Just another blogs.yokogawa.com Sites site\",\"publisher\":{\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"tr\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#organization\",\"name\":\"Chemical Pharma Blog\",\"url\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"tr\",\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/05\/yokogawa-logo-e1651674418793.png\",\"contentUrl\":\"https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/05\/yokogawa-logo-e1651674418793.png\",\"width\":302,\"height\":89,\"caption\":\"Chemical Pharma Blog\"},\"image\":{\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#\/schema\/person\/a1d9373fe7371d03437657ff780101fc\",\"name\":\"Yokogawa Turkey editorial team\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"tr\",\"@id\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#\/schema\/person\/image\/eb7b39e5322a2671185587b917ac944a\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ab25ab0cf0d90880ee1fb2cbfbd4b096?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ab25ab0cf0d90880ee1fb2cbfbd4b096?s=96&d=mm&r=g\",\"caption\":\"Yokogawa Turkey editorial team\"},\"url\":\"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/author\/yokogawa-turkey\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m - Chemical Pharma Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/","og_locale":"tr_TR","og_type":"article","og_title":"Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m","og_description":"Risk tabanl\u0131 Yokogawa siber g\u00fcvenlik y\u00f6netimi ile ilgili daha detayl\u0131 bilgi i\u00e7in makalemizi okuyabilirsiniz.  Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m Devam\u0131 &raquo;","og_url":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/","og_site_name":"Chemical Pharma Blog","article_published_time":"2021-05-28T09:24:55+00:00","article_modified_time":"2022-06-17T07:02:35+00:00","og_image":[{"width":901,"height":608,"url":"https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4.jpg","type":"image\/jpeg"}],"author":"Yokogawa Turkey editorial team","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/#article","isPartOf":{"@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/"},"author":{"name":"Yokogawa Turkey editorial team","@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#\/schema\/person\/a1d9373fe7371d03437657ff780101fc"},"headline":"Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m","datePublished":"2021-05-28T09:24:55+00:00","dateModified":"2022-06-17T07:02:35+00:00","mainEntityOfPage":{"@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/"},"wordCount":2413,"commentCount":0,"publisher":{"@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#organization"},"keywords":["CIS","IEC","ISA","ISO","IT","ITS","NIST 800","NIST CSF","OT","PLC","risk de\u011ferlendirmesi","Security","SIS-Safety Instrumented System"],"articleSection":["Emniyet &amp; G\u00fcvenlik","Optimizasyon"],"inLanguage":"tr","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/","url":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/","name":"Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m - Chemical Pharma Blog","isPartOf":{"@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#website"},"datePublished":"2021-05-28T09:24:55+00:00","dateModified":"2022-06-17T07:02:35+00:00","breadcrumb":{"@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/#breadcrumb"},"inLanguage":"tr","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/risk-degerlendirmesi-ot-ortamini-guvence-altina-almaya-yonelik-ilk-adim\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/"},{"@type":"ListItem","position":2,"name":"Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m"}]},{"@type":"WebSite","@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#website","url":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/","name":"Chemical Pharma Blog","description":"Just another blogs.yokogawa.com Sites site","publisher":{"@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"tr"},{"@type":"Organization","@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#organization","name":"Chemical Pharma Blog","url":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/","logo":{"@type":"ImageObject","inLanguage":"tr","@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#\/schema\/logo\/image\/","url":"https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/05\/yokogawa-logo-e1651674418793.png","contentUrl":"https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/05\/yokogawa-logo-e1651674418793.png","width":302,"height":89,"caption":"Chemical Pharma Blog"},"image":{"@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#\/schema\/person\/a1d9373fe7371d03437657ff780101fc","name":"Yokogawa Turkey editorial team","image":{"@type":"ImageObject","inLanguage":"tr","@id":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/#\/schema\/person\/image\/eb7b39e5322a2671185587b917ac944a","url":"https:\/\/secure.gravatar.com\/avatar\/ab25ab0cf0d90880ee1fb2cbfbd4b096?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ab25ab0cf0d90880ee1fb2cbfbd4b096?s=96&d=mm&r=g","caption":"Yokogawa Turkey editorial team"},"url":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/author\/yokogawa-turkey\/"}]}},"uagb_featured_image_src":{"full":["https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4.jpg",901,608,false],"thumbnail":["https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4-150x150.jpg",150,150,true],"medium":["https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4-300x202.jpg",300,202,true],"medium_large":["https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4-768x518.jpg",768,518,true],"large":["https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4.jpg",901,608,false],"1536x1536":["https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4.jpg",901,608,false],"2048x2048":["https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4.jpg",901,608,false],"post-thumbnail":["https:\/\/www.yokogawa.com\/eu\/blog\/app\/uploads\/sites\/8\/2022\/06\/4-4-356x200.jpg",356,200,true]},"uagb_author_info":{"display_name":"Yokogawa Turkey editorial team","author_link":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/author\/yokogawa-turkey\/"},"uagb_comment_info":0,"uagb_excerpt":"Risk tabanl\u0131 Yokogawa siber g\u00fcvenlik y\u00f6netimi ile ilgili daha detayl\u0131 bilgi i\u00e7in makalemizi okuyabilirsiniz. Risk De\u011ferlendirmesi: OT ortam\u0131n\u0131 g\u00fcvence alt\u0131na almaya y\u00f6nelik ilk ad\u0131m Devam\u0131 &raquo;","_links":{"self":[{"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/posts\/10971"}],"collection":[{"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/users\/147"}],"replies":[{"embeddable":true,"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/comments?post=10971"}],"version-history":[{"count":0,"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/posts\/10971\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/media\/10986"}],"wp:attachment":[{"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/media?parent=10971"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/categories?post=10971"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/tags?post=10971"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.yokogawa.com\/eu\/blog\/chemical-pharma\/tr\/wp-json\/wp\/v2\/coauthors?post=10971"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}