期刊文献+

信息技术产品安全可控内涵及其评价指标 被引量:8

The Explanation and of Evaluation Index to Controllability for Security of Information Technology Products
下载PDF
导出
摘要 介绍了国内外提升信息技术产品的安全可控水平的主要做法,分析了信息技术产品的安全可控风险,界定了安全可控的概念和内涵。为保障应用方安全可控需求和衡量信息技术产品安全可控程度,提出了信息技术产品安全可控评价指标体系。 This paper introduces the main practices to enhance the level of the controllability for security of information technology products at home and abroad. Analyzes the security risk of information technology products, and explicit the concept and connotation of controllability for security, In order to enstire user's requirement of the controllability for security and measure the degree of controllability for secnrity of information technology products, the paper proposes the controllability evaluation index system for security of information technology products
作者 王闯 王超
出处 《信息技术与标准化》 2017年第5期10-14,共5页 Information Technology & Standardization
基金 中国工程院咨询研究项目"我国信息领域产业发展策略研究" 编号:2016-xz-06
关键词 信息技术产品 信息安全 安全可控 信任 评价指标 information technology product informaation security controllability for security trust evaluation index
  • 相关文献

参考文献10

二级参考文献24

  • 1冯登国,张阳,张玉清.信息安全风险评估综述[J].通信学报,2004,25(7):10-18. 被引量:307
  • 2朱岩,杨永田,张玉清,冯登国.通用标准CC的研究与实现[J].小型微型计算机系统,2005,26(7):1174-1178. 被引量:2
  • 3NIST. Notional Supply Chain Risk Management Practices for Federal Information Systems[M]. Gaithersburg: NIST, 2012.
  • 4ISO/IEC. ISO/IEC WD 27036-3. Information technology--Security techniques--Information security for supplier relationships Part 3: Guidelines for ICT supply chain[S]. ISO/IEC, 2011.
  • 5王祯学,周安民,方勇,等.信息系统安全风险估计与控制理论[M].北京:科学出版社,2011:23-27.
  • 6NIST SP800-161 Supply Chain Risk Management Practices for Federal Information Systems and Organizations (Second Draft ) [S]. June, 2014.
  • 7Boyson S. Cyber supply chain risk management: Revolutionizing the strategic control of critical IT systems[J]. Technovation, 2014, 34(7): 342-353.
  • 8Linton J D, Boyson S, Aje J. The challenge of cyber supply chain security to research and practice--An introduction[J]. Technovation, 2014, 34(7): 339-341.
  • 9ISO/IEC 27036-3:2013 Information technology-- Security techniques--Information security for supplier relationships--Part 3: Guidelines for ICT supply chain.
  • 10NIST SP800-161 Supply Chain Risk Management Practices for Federal Information Systems and Organizations.

共引文献53

同被引文献41

引证文献8

二级引证文献37

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部