期刊文献+

关键信息基础设施网络安全框架研究(上) 被引量:6

Research on Critical Information Infrastructure Cyber Security Framework(Part One)
下载PDF
导出
摘要 关键信息基础设施的安全防护应以风险管控为出发点,建立一套识别、保护、检测、响应、恢复为核心的基础性、通用性安全框架,关键信息基础设施运营单位可以根据统一的安全框架,制定符合自身应用需求的标准或行业实践指南。通过研究NIST《改善关键基础设施网络安全的框架》的制定、实施和持续改进过程,分析了该框架的网络安全能力成熟度模型(C2M2)实践和该框架应用于我国的可行性,并对我国进行关键信息基础设施保护的方法与标准化工作提出建议。 The security protection of critical information infrastructure should take the risk control as the starting point, and establish a set of basic and general security framework with identification, protection, detection, response and recovery as the core. The critical information infrastructure operating unit can formulates its application requirements and practice guidelines according to the unified security framework. In this paper, we study the NIST "Framework for Improving Critical Infrastructure Cyber Security" formulation, implementation and continuous improvement process, analyze the framework of Cybersecurity Capability Maturity Model (C2M2) practice and the feasibility of the framework applied in our country. The method for protection of critical information infrastructure in our country and standardization are also proposed.
作者 刘贤刚 陈星
出处 《信息技术与标准化》 2016年第7期43-46,共4页 Information Technology & Standardization
关键词 关键信息基础设施 框架 网络安全 能力成熟度模型 critical information infrastructure framework cyber security capability maturity model
  • 相关文献

引证文献6

二级引证文献14

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部