节点文献
企业ISMS的体系建设与实施应用研究
【作者】 刘星;
【导师】 戴伟辉;
【作者基本信息】 复旦大学 , 项目管理, 2011, 硕士
【摘要】 随着计算机及互联网的日益迅猛的发展,信息技术无孔不入的渗透到了世界的每个角落,改变着人们的工作和生活方式。现代企业及商业机构业务的开展对信息系统的依赖程度越来越高,开放、复杂的信息系统面临着诸多风险,信息安全已变得至关重要。世界各国无论在社会层面还是在商业领域均出现了不容忽视的信息安全问题。现代企业利用信息系统提高市场响应速度。在提高效率降低库存的同时,通过信息化手段去管理上下游的业务伙伴、客户关系,逐渐形成以品牌和效率为核心竞争力的业务模式。此业务模式的特性决定了信息系统拥有“具有现金价值的数据”。包括销售数据、用户资料、业务订单、业务处理数据等,数据丢失及越权使用意味着直接的经济损失。而企业日益复杂庞大的信息系统无时无刻不在面临的来自于内部和外部的威胁,包括木马、病毒、蠕虫、恶意用户等。企业内部信息安全策略配置不当、流程缺失、人员安全意识不强、技术水平不足等一些列矛盾日益凸显。本文针对上述问题进行了探索性研究,围绕企业信息安全管理体系(ISMS, Information Security Management System)建立及其核心的风险评估的方法展开论述。在查阅了大量国内外文献资料的基础上,结合作者长期积累的实践经验,通过分析企业实际的安全需求,提出多维度的企业信息安全机制设计,细致描述了企业安全架构设计及企业ISMS的实施方法,并通过企业ISMS建设案例讲述上述方法在实际企业中的应用。期望通过本课题的研究对于完善企业的信息安全管理体系有所帮助。
【Abstract】 With the increasingly rapid development of computer and internet, information technology has penetrated into every corner of the world, changing people’s work and lifestyle. Business development of modern enterprises and commercial institutes has become more and more dependent on information system, open and complex information system faces various risks, and information security has become vital. Information security problem arises in every country in the world no matter on social dimension or commercial sector.Modern enterprises improve time to market by means of information system. They manage upstream and downstream business partner and customer relation via information means, at meanwhile increasing efficiency and decreasing stock, and gradually forming business model of brand and efficiency as core competence, and feature of this business model has determined that information system possesses data with cash value, which includes sales date, customer information, business order, business process data etc, data loss and abuse means direct economic losses. While the increasingly huge enterprise information system is facing menace all the time from both inside and outside, such as Trojan, virus, worm, malicious user etc. series of problems like enterprice inside information security strategy deficiency, procedure absence, security conscience shortage, lack of technology has become more and more apparent.This article probes into above mentioned problem, and discusses enterprise ISMS system setup and the core risk analysis method.based on reading large volume of documents home and abroad, combined with the writer’s long-cumulated experience, by analysis of enterprise security requirement, this article has put forward multi-dimension information security system and enterprise security architecture designing method and application in reality. I wish the research on this subject will help reimprovement on enterprise information security management system.
- 【网络出版投稿人】 复旦大学 【网络出版年期】2012年 08期
- 【分类号】TP393.08
- 【被引频次】2
- 【下载频次】173