期刊文献+

电子商务信息系统安全管理体系PRS-ISMS的研究 被引量:4

Research on Secure Management System PRS-ISMS of E-Commerce Information System
原文传递
导出
摘要 信息是电子商务至关重要的资产,电子商务的正常运转必须建立在安全的信息系统之上,因而电子商务信息系统安全问题成为人们日益关注的重点.根据电子商务信息系统特点,从信息系统过程(Process)、资源(Resource)和安全目标(Security)三个视角分析了电子商务信息安全风险的要素及其关系,构建了三维信息系统安全管理体系模型PRS-ISMS,提出了改进的信息安全风险管理过程PRS-PDCA. Security issues on e-commerce information system is becoming increasingly im- portant as information is a kind of critical e-commerce asset, as well as the normal operation of e-commerce must be built on secure information system. In this article, elements of infor- mation security risks and their relationships are analyzed and the three-dimensional secure system model PRS-ISMS and improved management process PRS-PDCA of information sys- tem are built from such views as information system Resource, information system process and security objectives based on the characteristics of the e-commerce information system.
出处 《数学的实践与认识》 CSCD 北大核心 2010年第11期112-118,共7页 Mathematics in Practice and Theory
基金 山东省教育厅科技计划项目(J07JY14)
关键词 电子商务 信息系统 信息安全管理体系 信息安全管理过程 e-commerce information system information secure management system information secure management process
  • 相关文献

参考文献13

  • 1信息技术-安全技术-信息安全管理体系-要求[s].ISO/IEC27001:2005,IDT.
  • 2信息技术-安全技术-信息安全管理实用规则[s].ISO/IEC27002:2007,IDT.
  • 3信息安全风险评估指南[s].
  • 4ISO/IEC 17799: 2000, Information Technology-code of Practice for Information Security Management[S]. 2000, 12.
  • 5ISO/IEC 13335-1(1997-01), Information Technology-Guidelines for the Management of IT Security- Part 1:Concepts and Models for IT Security.
  • 6I SO/IEC 13335-2(1998-01), Information Technology-Guidelines for the Management of IT Security- Part 2: Managing and Planning IT Security.
  • 7ISO/IEC 13335-3(1998-06), Information Technology-Guidelines for the Management of IT Security- Part 3: Techniques for the Management of IT Security.
  • 8ISO/IEC 13335-4(2000-03), Information Technology-Guidelines for the Management of IT Security- Part 4:Selection of Safeghards.
  • 9COBIT 4.0. Control Objectives for Information and related Technology. Version 4.
  • 10James J, Jiang, Gray Klein. Software. Development Risk to Project Effectiveness[J]. The Journal of Systems and Software, 2000(8): 3-10.

二级参考文献1

  • 1郭仲伟,风险分析与决策,1992年

共引文献19

同被引文献9

引证文献4

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部