摘要
本文建立了三维结构的铁路网络与信息安全管理体系,分别从技术要素、管理要素和信息安全生命周期的角度对铁路信息安全风险进行深刻剖析。技术因素主要分为环境安全、系统安全、网络安全与应用安全;管理因素主要分为人员、机构和制度;信息系统生命周期从规划、设计、实施、运维到废弃的全生命周期过程中,针对技术因素的各个方面,都从安全风险的识别、评估和控制三个层次的纵深防御体系,进行了深入的研究与分析。本文对于有效降低铁路信息安全风险,提高铁路信息系统的安全性,保障铁路网络和信息系统安全、持续、稳定运行有着积极的推动与借鉴作用。
The paper established the three-dimensional structure of the railway network and inforlnation security management system. The system discussed the railway information security risk deeply in the perspective of technical factors, management factors and the information security life cycle respectively. Technical factors included environment security, system security, network security and application security. Management factors were divided into personnel management, organization and regulations. Information system life cycle was divided into five stages, they were planning, design, implementation, operations to abandonment. During the whole life cycle, according to all aspects of the technical factors, a thorough research and analysis was carried on in the perspective of safety risk identification, risk assessment and risk control The paper was meanningful to reduce the railway information security risks, improve the security of railway information system, ensure the safety of railway network and information system.
出处
《铁路计算机应用》
2014年第6期24-28,共5页
Railway Computer Application
基金
铁道部重点课题:(2012F032)
中国铁路总公司重大课题:(2013X010A)
关键词
铁路信息安全
风险管理
安全管理体系
信息系统生命周期
railway information security
risk management
safety risk management system
life cycle of Information System