期刊文献+

构建云计算环境的安全检查与评估指标体系 被引量:11

Building Security Check and Risk Assessment Index System on Cloud Computing Environment
下载PDF
导出
摘要 在云计算日益发展并广泛应用的浪潮下,云计算环境的安全问题也引起了业界的重视。文章首先对云计算环境安全现状进行分析,通过对云计算安全保护结构的深入研究,建立云计算环境安全保护基本要求框架;然后给出框架中具体指标项的构建方法,即从风险分析角度出发,通过实际环境安全需求调研、云安全事件以及国内外相关研究成果分析,对云计算框架中的保护对象在面临存在的风险时,应该采取何种有效措施提出要求,进而得出相应测评指标项;最后给出指标打分模型来测量和评价云计算环境的安全风险及安全保护措施的有效性。文章研究成果可为国家制定云计算安全相关标准以及有关机构履行云计算环境的检查评估职责提供参考。 With the increasing development and wide application of cloud computing, the issue of security in cloud computing environment has attracted more attentions in technology information. Initially, this article involves in analyzing the status of security in cloud computing environment. It establishes the framework for cloud computing environment security under basic requirements through the deep research of this subject. In addition, it clearly identiifes the speciifcations and methods required by this framework. It focuses on considering the risk analysis, the actual environmental safety requirements investigation, cloud security event analysis and related research achievements. From above, it takes effective measures when the protection objects faces risks in cloud computing framework and then draws the corresponding manipulated variables. Finally, according to marking model, it can measure and evaluate the security risks in cloud computing environment and the efifciency of security measures. This article could provide the relative reference for the relevant departments to develop cloud computing security standards and fulifll the evaluation of inspection and duty.
作者 章恒 禄凯
机构地区 国家信息中心
出处 《信息网络安全》 2014年第9期115-119,共5页 Netinfo Security
基金 国家发改委2012年信息安全专项
关键词 云计算 安全 安全检查 风险评估 指标体系 cloud computing security security check risk assessment index system
  • 相关文献

参考文献11

  • 1Assessing the Security Risks of Cloud Computing[R]. Gartner, 2008.
  • 2Top Threats to Cloud Computing V1,0[R], Cloud Security Alliance,2010.
  • 3The Notorious Nine Cloud Computing Top Threats in 2013[R].Cloud Security Alliance, 2013.
  • 4云控制矩阵(CCM)V3.0[R].Cloud Security Alliance, 2013.
  • 5NIST 800—144: Guidelines on Security and Privacy in Public CloudComputing [R]. National Institute of Standards and Technology,USA,2011.
  • 6关于国内外云计算组织有关标准分析[R]. ISO/IEC JTC1 SC38,2011.
  • 7信息安全技术云计算服务安全指南(国标征求意见稿)[S].
  • 8信息安全技术云计算服务安全能力要求(国标征求意见稿)[S].
  • 9基于云计算的互联网数据中心安全指南(送审稿)[S].
  • 10NIST 800—53: Security and Privacy Control for Federal InformationSystems and Organizations[R]. National Institute of Standards andTechnology,USA, 2010.

同被引文献96

引证文献11

二级引证文献47

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部