首页 | 本学科首页   官方微博 | 高级检索  
     

信息系统安全等级保护能力构成框架研究
引用本文:陈雪秀,任卫红,谢朝海.信息系统安全等级保护能力构成框架研究[J].信息网络安全,2008(9):30-32.
作者姓名:陈雪秀  任卫红  谢朝海
作者单位:公安部信息安全等级保护评估中心
基金项目:国家高技术研究发展计划(863计划)
摘    要:本文首先从威胁与安全保护能力之间的关系出发,说明威胁和安全保护能力通过信息系统中的业务信息和系统服务相互作用、相互影响。同时提出安全保护能力分级,不同安全等级的信息系统应具有与其等级相适应的安全保护能力。然后从安全技术和安全管理两方面,提出信息系统等级保护能力构成框架,把保护能力分为防护类、检测类、恢复响应类、制度类、组织人员类、安全工程类和安全运行类。最后在信息系统等级保护能力构成框架指导下,分析了不同级别保护能力的体现,为信息系统选择措施进行恰当保护以到达相对安全提供指导,也为信息系统安全等级保护基本要求提供理论依据。

关 键 词:等级保护  保护能力构成框架  业务信息  系统服务

Research on Framework of Information classified Security Protection Capability
CHEN Xue-xiu,REN Wei-hong,XIE Chao-hai.Research on Framework of Information classified Security Protection Capability[J].Netinfo Security,2008(9):30-32.
Authors:CHEN Xue-xiu  REN Wei-hong  XIE Chao-hai
Affiliation:(MPS Information Classified Security Protection Evaluation Center, Beijing 100142, China )
Abstract:Firstly, this paper studies on relationship between threat and security protection capability, explains that they interact by business information & system service of information system. At the same time, points out that security protection capability need to be classified, and the capability must be accord with information system' s security protection classification. Then we points out framework of protection capability from two aspects of security technology and management. And protection capacity is divided into different sorts, including protection, testing, resume & response, system, organization & person, security engineering, security operation and so on. Lastly, analyzes main embodiment of different classify protection capacity based on this framework. All these guide to choose security measure that they properly protect information system and make it relatively security, and provide theory basis for developing basic requirements for classified information system security.
Keywords:classified security protection  framework of protection capability  business information  system service
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号