节点文献

面向ISO27001的本体建模及其应用——以企业恶意软件防护为例

ISO27001-Oriented Ontology Modeling and Its Application——Malware Prevention in Enterprises

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 濮烨青张保稳

【Author】 PU Ye-qing;ZHANG Bao-wen;Shanghai Jiaotong University;

【机构】 上海交通大学

【摘要】 信息安全标准已经逐渐成为企业整体信息防护的必要选择。ISO27000系列标准是国际上较为常用的一个安全标准框架。利用本体工具,对ISO27001安全标准的管理体系建设和系统实际要求两个方面进行本体建模。一方面梳理ISMS(企业信息安全管理体系)的逻辑结构,以便企业进行管理体系建立情况的自查,一方面利用本体构建系统中与标准要求相关的主客体及其关系,给出一种验证系统对标准的符合性方法。以恶意软件防护为例,构建相关文档体系结构和系统具体要求。通过实例验证,证明了所提方法能够较为客观地推理系统在恶意软件防护方面对安全标准的符合性,能降低人工评审的主观性,为标准的自动化评审作出创新性探索。

【Abstract】 Infosec framwork increasingly becomes the necessary choice of an enterprise in its information protection on the whole. ISO/IEC 27001 is one of the most widely-used infosec standard frameworks. With ontology tool, the architecture and implementation of ISMS is ontologically modeled. The architecture could help the enterprise establish the document scheme of its ISMS while the implementation integrate the requirements made by the standard into a model system. Here the malware prevention is taken as an example for an automatic approach in measuring the compliance of a system with the standard framework, and this is an innovative exploration on the automatic verification process of ISO27001.

【关键词】 ISO27001恶意软件防护本体protégé
【Key words】 ISO27001malware preventionontologyprotégé
【基金】 国家自然科学地区科学基金项目(No.61562004);科技部国家重点研发计划(No.2016YFB0800100,No.2016YFB0800105)~~
  • 【文献出处】 通信技术 ,Communications Technology , 编辑部邮箱 ,2017年02期
  • 【分类号】TP309
  • 【被引频次】3
  • 【下载频次】114
节点文献中: 

本文链接的文献网络图示:

本文的引文网络