摘要
FedRAMP是美国联邦政府用于对云服务实施安全评估、授权和监测的标准化程序。本文通过对FedRAMP的研究,从政府监管、技术可控、产业化等角度出发,提出将云服务纳入到我国等级保护工作范畴内,实现云服务的安全可控,从而在云计算环境下进一步推进我国等级保护工作的开展。
FedRAMP, as a standardized program used by US Federal Government, provides security assessment, authorization, and monitoring for cloud services. Based on the study of FedRAMP, and from the aspects of government supervision, controllable tech- nique and industrialization, this paper proposes the idea that the cloud service should be incorporated into the working scope of state classified protection , thus to achieve secure and controllable cloud service, and consequently to promote the state classified protection under the condition of cloud computing.
出处
《信息安全与通信保密》
2015年第8期73-77,81,共6页
Information Security and Communications Privacy