期刊文献+

美国联邦信息安全风险管理框架及其相关标准研究 被引量:11

Study for Federal Information Security Risk Management Framework and Related Standards
原文传递
导出
摘要 论文首先概述了美国联邦信息安全风险管理框架的实现及其相关标准,接着对NIST风险管理框架的八个步骤进行了详细描述;最后在对中国的等级保护三步式和美国FISMA的三阶段进行简单分析比较的基础上,根据中国信息化建设及管理的现状,对中国下一步等级保护工作提出了看法。 This paper first introduced the realization of the Federal Information Security Risk Management Framework and related standards, then described the eight steps of the National Institute of Standards and Technology(NIST) risk management framework in detail. At the end, viewpoints about Chinese information classified security protection were given according to current status of the information-base construction and management, which were based on the brief analytical comparison of Chinese "three steps" information classified security protection and "three stages" pattern of the Federal Information Security Management Act(FISMA).
出处 《信息安全与通信保密》 2009年第2期40-44,共5页 Information Security and Communications Privacy
关键词 信息安全 风险管理 FISMA Information security Risk management FISMA
  • 相关文献

参考文献10

  • 1.Minimum Security Requirements for Federal Information and Informa-tion Systems[].NIST FIPS PUB.2006 被引量:1
  • 2Volume I Revision 1 Guide for Mapping Types of Information and Information Sys-tem toSecurity Categories. NIST SP 800-60 . 2008 被引量:1
  • 3Volume II Revision 1 Guide for Mapping Types of Information and Information Sys-tem to Security Categories. NIST SP 800-60 . 2008 被引量:1
  • 4Revision 2,Recommended Security Controls for Federal Information Systems. NIST SP 800-53 . 2007 被引量:1
  • 5Managing Risk from Information Systems:An Organizational Perspective. NIST SP 800-39 . 2008 被引量:1
  • 6Guide for Developing Security Plans for Federal Information Systems. NIST SP 800-18 . 2006 被引量:1
  • 7Revision 1 (Draft) National Checklist Program for IT Products—Guidelines for Checklist Users and Developers (Draft). NIST SP 800-70 . 2008 被引量:1
  • 8.Guide for Assessing the Security Controls in Federal Information Systems[].NIST SP -A.2008 被引量:1
  • 9Revision 1 Guide for Security Authorization of Federal Information Systems. NIST SP 800-37 . 2008 被引量:1
  • 10.Standards for security categorization of federal information and information systems[]..2004 被引量:1

同被引文献60

引证文献11

二级引证文献45

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部