期刊文献+

基于Zachman框架的复杂信息系统的系统安全架构 被引量:4

SYSTEM SECURITY ARCHITECTURE OF COMPLEX INFORMATION SYSTEM BASED ON ZACHMAN FRAMEWORK
下载PDF
导出
摘要 当前由信息技术与网络技术构成的信息系统已不单是完成信息的简单处理与传输,它已成为连接与融合众多的业务系统核心。以信息系统为核心,并由此构成的包含各类业务系统的系统,可协同完成一定的组织目标和业务流程,称之为复杂信息系统。主要研究并合理地划分复杂信息系统中的不同层面的风险管理层次。研究采用国际上流行的Zachman框架,结合《GB/T 20274-2008信息安全技术信息系统安全保障评估框架》,构建复杂信息系统安全架构。该架构可用于复杂信息系统分层划分及其评估。 The information system composed of information technology and Internet technology is no longer just simply processing and transmitting information, it has also become the core that connects and integrates many business systems. Using information system as the core, the system, which comprises all kinds of business systems and can collaboratively fulfil certain objectives of the organisation and business process, is called the complex information system. This paper mainly studies and reasonably classifies risk management level of complex information system at different levels. The research uses the framework of Zachman which is popular in the world, and combines "GB/T 20274-2008 safety assessment framework of information security technology of information system security" to build a security architecture complex information system. The architecture can be used for the division and evaluation of hierarchical of complex information system.
机构地区 华东理工大学
出处 《计算机应用与软件》 CSCD 2015年第9期92-96,共5页 Computer Applications and Software
基金 国家信息安全测评中心项目(CNITSECKY-2012-006/2)
关键词 复杂信息系统 Zachman框架 风险管理层次 业务建模 Complex information system Zachman framework Risk management level Business modelling
  • 相关文献

参考文献14

二级参考文献17

  • 1(美)Roger Sessions.企业精简架构[M].机械工业出版社. 被引量:1
  • 2余彤鹰.Zachman企业架构框架若干分析.企业工程论坛,http://www.ee-forum.org/pub/ty/2010-02-p1198.html. 被引量:1
  • 3SHANNON C E.Communication theory of secrecy systems[J].Bell System Technical Journal,1949,28:656-175. 被引量:1
  • 4BELL D E,LAPADULA L J.Secure computer system:unified exposition and MULTICS interpretation,Revision 1,US air force ESD-TR-75-306[S].MITRE Corporation MTR2997,Bedford,MA,1976-03. 被引量:1
  • 5GOGUEN J A,MESEGUER J.Security policies and security models[C]//Proc of IEEE Symposium on Security and Privacy,IEEE,1982:11-20. 被引量:1
  • 6GB/T 18336-1,2信息技术安全性评估准则[S].2001-03. 被引量:1
  • 7NSTISSI 4009 National Information Systems Security(INFOSEC)Glossary[S],1997-08. 被引量:1
  • 8Common Criteria for Information Technology Security Evaluation(CC)Version 2.1[S],1999-08. 被引量:1
  • 9PAULK M C,CURTIS B,WEBER C,et al.CMU/SEI-93-TR-24[S].Software Engineering Institute,1993-02. 被引量:1
  • 10Information assurance technical framework,Release 3.1[S].2002-09. 被引量:1

共引文献25

同被引文献17

引证文献4

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部