信息网络安全 ›› 2016, Vol. 16 ›› Issue (9): 177-183.doi: 10.3969/j.issn.1671-1122.2016.09.036

• • 上一篇    下一篇

基于信息安全等保标准的网络安全风险模型研究

李涛(), 张驰   

  1. 重庆市公安局网络安全保卫总队,重庆401121
  • 收稿日期:2016-07-25 出版日期:2016-09-20 发布日期:2020-05-13
  • 作者简介:

    作者简介: 李涛(1981—),男,重庆,工程师,硕士,主要研究方向为信息安全;张驰(1989—),男,重庆,工程师,硕士研究生,主要研究方向为信息安全。

Research on Network Security Risk Model Based on the Information Security Level Protection Standards

Tao LI(), Chi ZHANG   

  1. Chongqing Bureau of Public Safety, Chongqing 401121, China
  • Received:2016-07-25 Online:2016-09-20 Published:2020-05-13

摘要:

信息安全等级保护是信息系统必不可少的安全保障,其要求不同安全等级的系统应具有不同的安全保护能力,通过在安全技术和安全管理上选用与安全等级相适应的安全控制来实现。文章着眼于三级信息系统安全等保测评的一个重要方面——网络安全,通过建立反映其安全状况和风险威胁的风险评估模型,对三级系统等保网络安全层面的安全控制模块进行风险评估分析研究,对不同安全侧重点的系统进行安全评价,反映系统的总体网络架构和各关键网络设备的安全保护情况,进而更精确地得到不同风险对系统的影响,可更有效地对安全风险进行控制和预防,为系统的安全决策提供有力支持和安全保障。

关键词: 等级保护, 网络安全, 风险评估, 测评模型, 信息安全

Abstract:

Information security level protection is an important guarantee of information system. It requires that different level information system should have the different security proctection which is realized by using suitable security control on security technology and system management. The paper focuses on an important aspect of the three information system security assessment of the level of protection assessment model, the three-tier grading system information network security level to protect the safety control module for risk assessment analysis to accurately focus on different security information systems security evaluation accurately reflects the overall network architecture and all critical information systems security of the network devices. Based on the assessment model, the most common major information systems - three information systems, "Network security risk assessment based on the information system security protection standards."Derived by analyzing three information systems risk assignment, and then get a more precise impact of different risk levels for each system can more effectively control security risks and prevention, provide strong support for the safety and security of information systems decisions protection.

Key words: classified protection, network security, risk assessment, evaluation model, information security

中图分类号: