节点文献

基于ISO27000的复合图书馆信息安全风险评估理论与实证研究

Study of Theory and Example of Information Security Risk Assessment of Hybrid Library Based on ISO27000

【作者】 朱晓欢

【导师】 黄水清;

【作者基本信息】 南京农业大学 , 情报学, 2007, 硕士

【摘要】 信息时代,随着图书馆自动化、数字化及网络化建设的不断发展,当代图书馆正逐步由传统型图书馆向数字型图书馆迈步。“复合图书馆”作为传统和数字的结合体,作为目前高校图书馆、公共图书馆和科学图书馆的普遍存在形式,正面临着新的挑战——数字信息资源急剧增加,新的业务不断涌现,网络服务方式也日益兴起。正因如此,如何保证信息资源准确无误的为用户服务、如何确保图书馆各项业务持续稳定的开展、如何有效避免网络威胁对图书馆应用系统的侵害等,都对复合图书馆的信息安全提出了更高的要求。我们有必要对复合图书馆实施信息安全风险评估和管理以保障其安全。本文首先对图书馆领域的信息安全现状进行了理论研究。一方面总结了目前信息安全领域较流行的一些安全技术,如防火墙技术、反病毒技术、入侵检测技术和VPN技术等;另一方面以中国社会科学引文索引(CSSCI)收录的信息安全领域发表的期刊论文数据为依据,辅以中国期刊网的数据,从发文量和被引量两个角度分析并总结了国内该领域的研究现状。接着本文对目前国内外图书馆界的研究热点——数字图书馆的信息安全进行了文献研究,并概述了安全技术、安全管理和安全政策等方面的内容。为了更好对复合图书馆开展信息安全管理,本文选取目前国际上通用的具有代表性的信息安全管理标准ISO27000系列,以该系列下的ISO27001标准和ISO17799标准所提出的风险评估方法和信息安全管理控制措施等为指导,对复合图书馆实施信息安全风险评估,为开展风险管理做好准备。本文的实证研究部分,选取目前国内已开展数字图书馆项目的高校图书馆、公共图书馆和科学图书馆为调研对象,对其信息安全状况进行了调研,并依据ISO27000的风险评估标准内容对调研对象进行了风险分析和评估。通过对调研所得数据进行收集、归纳、比较和分析,本文提出了基于ISO27000的针对复合图书馆信息安全的风险评估实施模型。该模型根据ISO27000提出的风险评估步骤,结合复合图书馆的业务特点,分别从信息资产、威胁和薄弱点三个安全要素对复合图书馆的信息安全风险进行分析和评价,评估所得结果是复合图书馆日后实施信息安全风险管理的前提。最后,本文结合某一被调研的高校图书馆依据该模型实施风险评估的过程,从实例的角度验证了基于ISO27000的复合图书馆信息安全风险评估实施模型的适用性和可行性。本文所提出的基于ISO27000的复合图书馆信息安全风险评估实施模型将有助于复合图书馆业务部门开展信息安全风险自评估,为信息安全风险管理和信息安全保障体系的建立打下基础。

【Abstract】 In the information age, with the development of library automatization, digital and network construction, Modern Library is gradually from the traditional library to digital library moving. "Hybrid Library", as the combination of the traditional library and digital library, and as the prevalent form of university library, public library and scientific library, is now facing a new challenge: digital information resources increase dramatically, new business are constantly emerging, and network services approach is also increasingly rise. For these reasons, how to guarantee the accuracy of the information resources for customer service, how to ensure that the library continued stability operations, and how to avoid the threat of the library network application systems are encroached upon. Library Information security is higher demanded. We need to assess the security risk and management of hybrid library in order to protect its security.In this thesis, the first theoretical research is about library information security status. While summing up the current field of information security some of the most popular security technologies, such as Firewall technology, Anti-virus technology, Intrusion Detection Technology and the VPN, then, based on the data both from the China Social Sciences Citation Index (CSSCI) and China National Knowledge Infrastructure (CNKI), the thesis analyzes the domestic researches in the information security management field. Then it presents to the domestic and international library community hotspot: Digital Library for the security of information in the literature, and an overview of security technology, security management and security policy and other content.To better manage the information security of hybrid library, this thesis is based on the current international representative of the general information security management standard ISO27000 series, using the risk assessment methods, information safety management and control measures, from the ISO27001 and ISO17799, as a guide to assess the information security risk of hybrid library, for risk management preparedness.The example research components, has selected the current national digital library project of the University Library, public library and scientific library as research targets for their information security status of the investigation, then in accordance with the ISO27000 standard risk assessment as the object of study of risk analysis and assessment. According to research data collected, summarized, comparison and analysis, it present implement model of information security risk assessment of hybrid library based on the ISO27000. The model is under the ISO27000 risk assessment steps along with hybrid library operational characteristics. It analyses and evaluates security risk of hybrid library by analyzing three elements of security’s information, the information assets, threats and vulnerabilities. And the assessment results are preconditions of hybrid library’s security management. Finally, this thesis is a study of the college library model based on the implementation of the risk assessment process, examples from the perspective of ISO27000 certification based on security risk assessment of hybrid library for the implementation of the application and feasibility.This thesis proposed by the ISO27000-based hybrid library information security risk assessment model will help implement complex Library business sectors self assessing, in order to build the foundation of information security risk management and information security systems.

  • 【分类号】G250.7
  • 【被引频次】16
  • 【下载频次】665
节点文献中: 

本文链接的文献网络图示:

本文的引文网络