摘要
分析了ICT供应链风险管理的研究现状,解析了ICT供应链风险管理相关标准,并从ICT供应链风险的来源、管理以及安全控制方面重点探讨了NIST SP 800-161的主要内容。最后提出了积极制定符合我国国情的ICT供应链风险管理标准等工作建议。
In this paper, the current situation of ICT supply chain risk management is analyzed, the related standards are briefly the NIST S introduced. In addition, from the perspective of the risk sources, the management and the security controls, P 800-161 is introduced in detail. Finally, several suggestions for the ICT supply chain risk management are proposed, sucn as developing ICT supply chain risk management standards in line with our country's national conditions
出处
《信息技术与标准化》
2014年第6期20-23,36,共5页
Information Technology & Standardization
基金
信息安全标准综合验证与管理平台
项目编号:工信协函[2014]82号
信息安全关键标准研究能力建设
项目编号:工信协函[2013]116号
关键词
ICT供应链
风险管理
标准
ICT supply chain
risk management
standard