摘要
对常用的信息安全评估国际标准:CC、BS7799和SSE-CMM标准,在针对的问题和具体目的、安全工程过程中的关注点和评估反映的实质等方面存在的差异和联系进行了较为详细的对比分析,并指出在同一信息安全系统评估或安全产品开发中的相互结合的切入点。
This text discusses the characteristics of popular relevant standards of Information Security evaluation (e.g. CC, ISO 17799/BS 7799 and SSE-CMM) in the world at present. It is indicated that the difference and relation which CC, BS 7799 and the SSE-CMM standards in which aims at in the question and the concrete goal, the safety engineering process attention and evaluation reflection aspects and so on, finally points out in the identical information security system appraisal or security product development how to combined with each other.
出处
《信息技术与标准化》
2007年第11期27-29,共3页
Information Technology & Standardization