摘要
文章分析了电子商务环境下企业信息安全管理所面临的问题,借鉴ISO27001标准基于风险管理的思想,为企业设计了一套系统化、程序化和文件化的信息安全管理体系(ISMS),以期为企业信息安全实践指明方向,为安全控制措施的有效落实打下坚实的基础。
By analyzing the problems of the enterprise information security management under the environment of commerce environment,and studying the risk management idea of ISO27001,this paper designed a set of systematic,programmatic and documented information security management system(ISMS),which in order to guide the practices of the information security management and build up a solid foundations for implement safety control measures.
出处
《现代情报》
CSSCI
2011年第2期52-55,共4页
Journal of Modern Information