节点文献

信息系统的安全保障体系研究

Research on Security Assurance System of Information System

【作者】 刘春艳

【导师】 徐宝祥;

【作者基本信息】 吉林大学 , 情报学, 2006, 硕士

【摘要】 随着信息技术的发展,计算机信息系统已经成为整个国家机构运转的命脉和社会活动的支柱。而对信息系统的任何攻击、破坏或信息系统本身的漏洞、故障,都将对用户以至整个社会产生巨大影响。因此,研究信息系统的安全性具有重大的、直接的现实意义。本文首先深入分析了影响信息系统安全的因素及根源,引出了信息系统安全应该具有的需求和特点。之后,介绍并评析了目前典型的信息安全模型,借鉴各模型的特点,并运用了系统工程的思想,提出了一个信息系统的安全保障体系模型,该体系模型认为信息系统的安全保障工作应作为工程来实施。接下来,本文具体研究了构成安全保障体系的各要素,分别分析了信息安全策略、安全组织(人),安全工程过程(技术),安全管理以及相关的标准、法律法规。尤其重点介绍了安全工程过程(技术)的保障,以及安全管理的保障。

【Abstract】 It is valuable as a wealth of information, through which all activities in the human life. Information system is an organic which constitutes the information collection and processing methodologies, processes, technologies based on certain rules. It is open Internet applications management system based the computer and data communications network, is information collection, storage, processing, analysis and transmission tool. With the development of information technology in particular the network technology, it makes information systems facing many security risks, which network has openness, connectivity and freedom, and other characteristics. So it is more and more important that meet security needs of information systems and information throughout the confidentiality, authenticity, accessibility and controllability, and information systems security has become a worldwide concern and research focus and attention to difficult problems. The thesis studied the security of information systems, researching and analyzing the security assurance system model of information systems.The security theory and practice of information systems development is progressing, and it develops from earlier confidential communications to the attention of information confidentiality, integrity, availability, controllability and undeniableness, and further to today’s information security assurance and information security assurance systems. The thesis analyzed and compared the typical security models, such as the ISO security architecture models, P2DR and its derivative models, and so on. The ISO security architecture model has good guidance but too abstract, P2DR model has good practice guidance, emphasizing the importance of time and is dynamic and self-adaptive, but it doesn’t has the consideration of man’s importance and is short of management. On the contrary, this thesis presents an brand-new information system security assurance system model that should be based on the security strategy, people as the acting role, security technology as the body to support the implementation of security engineering system, safety management as a means to the relevant standards, laws and regulations as a guarantee, roundly and effectively to protect information systems security. These elements of the system are not isolated discrete, but complementary to each other and are mutually blend together for the role of information systems security. Next, the thesis analyzed and studied the factors of the assurance security system model one by one from within this field to the verge.

【关键词】 信息系统信息安全保障
【Key words】 Information SystemInformation SecurityAssurance
  • 【网络出版投稿人】 吉林大学
  • 【网络出版年期】2006年 12期
  • 【分类号】TP309
  • 【被引频次】12
  • 【下载频次】560
节点文献中: 

本文链接的文献网络图示:

本文的引文网络