摘要
阐述了ISO 28000、ISO/IEC 27036等IT供应链安全相关标准的进展,分析了美国现行的IT供应链安全风险管理措施,进一步明确了我国IT供应链安全风险管理标准定位,对制定我国IT供应链安全标准提出了建议。
This paper reviewed the advance of ISO 28000, ISO/IEC 27036,and other IT supply chain security standards, analyzed the American current risk management methods. At last, the paper further described the position of IT supply chain security standards in our country, and gave suggestions on developing our national IT supply chain security standards
出处
《信息技术与标准化》
2012年第6期16-19,共4页
Information Technology & Standardization
关键词
信息安全
IT供应链
标准化
information security
IT supply chain
standardization