期刊文献+

大型企业信息安全体系架构设计初探 被引量:6

Design of information security architecture of large-scalar enterprise.
下载PDF
导出
摘要 随着信息技术的发展和应用的不断深入,信息安全日益受到国家、企业和社会公众的关注。中国政府已经提出了构建国家信息安全保障体系的设想,明确了政府、企业和公民各自应承担的责任与义务。企业的信息安全工作,主要关注点是如何保障信息技术应用和防止企业商业秘密泄露。同时,大型企业特别是地理位置分布广泛的企业集团,在信息安全方面存在很多难点。分析了国内、国际信息安全现状和发展趋势,概述了Gartner的企业信息安全体系架构设计思想和国内大型企业面临的信息安全需求;从管理、技术、控制三个视角和概念、逻辑、实现三个层面阐述了构建企业信息安全体系架构的概念、内容和方法,提出了一种大型企业信息安全体系架构模型——MCT(管理-控制-技术)模型;针对大型企业实际情况,陈述了如何应用MCT模型进行信息安全体系架构设计;最后给出了一套可实施的从设计层到实现层的转换方法,即以项目为单位来组织具体的信息安全体系建设工作。 With the development and continuously deepening application of information technology,information security has attracted more and more attentions from states,enterprises and the general publics.Chinese government has proposed building a national information security system and defined clearly the respective responsibilities and obligations of government,enterprises and citizens.In order to enhance the ability of information security and comply with laws and regulations,enterprises must construct a complete information security system.This paper investigated the situations and development trends of domestic and international information security practices and researches,summed up the experience of Gartner company in enterprise information security architecture,introduced the concepts,contents and methods to construct enterprise information security architecture in terms of management,control,and technology and from conceptual,logic,and implementation layer levels,put forward a large-scale enterprise information security architecture model—MCT (Management-Control-Technology) model,illustrated the designing of information security architecture for a large-scalar enterprise with the MCT model,and finally described a practical conversion method from design to implementation,that is how to use project-specific units to construct information security system.
出处 《勘探地球物理进展》 2008年第6期471-478,共8页 Progress in Exploration Geophysics
关键词 信息技术 信息安全 信息系统 信息技术基础设施 信息安全体系架构 information technology (IT) information security information system IT infrastructure information security architecture
  • 相关文献

参考文献7

  • 1中华人民共和国国务院147号令.中华人民共和国计算机信息系统安全保护条例[EB/OL].(1994-02-18)[2008-10-04].http://www.tc260.org.cn/info-ViewF.jsp
  • 2国家质量技术监督局.GB17859-1999计算机信息系统安全保护等级划分准则[EB/QL].(1999-09-13)[2008-10-04].http://www.ga.dl.gov.cn/djbh/GB17859-1999.doc
  • 3公安部,国家保密局,国家密码管理局,等.关于印发《信息安全等级保护管理办法》的通知[EB/OL].(2007-06-22)[2008-09-17].http://www.gov.cn/gzdt/2007-07/24/content-694380.htm
  • 4Gartner Inc. Structure and content of an enterprise information security architecture.. Gartner research[EB/OL]. (2006 - 01 - 26) [2008 - 09 - 18]. http:// egovstandards, gov. in/egs/eswgS/enterprise-architecture-working-group-folder/gartners-reports/structure _ and content of an 136867. pdf
  • 5ISO/IEC 27001:2005. Information technology--Security techniques Information security management systems[EB/OL]. (2005 - 10 - 14)[-2008 - 10 - 04]. http://www.iso. org/iso/catalogue_detail? csnumber= 42103
  • 6ISO/IEC 27002 : 2005. Information technology--Security techniques--Code of practice for information security management[EB/OL]. [2008 - 10- 04]. http:// www. iso. org/iso/search.htm? qt= 27002&published= on&active_tab: standards
  • 7ISO/IEC 27005:2008. Information technology--Security techniques--Information security risk management [EB/OL]. (2008 - 06 - 04)[2008 - 10 - 04]. http:// www. iso. org/iso/iso _ catalogue/catalogue _ tc/cata- logue_detail.htm? csnumber=42107

共引文献1

同被引文献22

引证文献6

二级引证文献48

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部