信息网络安全 ›› 2019, Vol. 19 ›› Issue (11): 1-7.doi: 10.3969/j.issn.1671-1122.2019.11.001

• 等级保护 • 上一篇    下一篇

网络安全等级保护2.0云计算安全合规能力模型

张振峰1, 张志文1(), 王睿超2   

  1. 1.公安部信息安全等级保护评估中心,北京 100142
    2.阿里云计算有限公司,北京 100102
  • 收稿日期:2019-09-16 出版日期:2019-11-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:张振峰(1982—),男,北京,副研究员,硕士,主要研究方向为网络安全等级保护、云计算安全合规能力评估;张志文(1991—),男,山西,硕士,主要研究方向为网络安全等级保护、云计算安全;王睿超(1989—),男,北京,硕士,主要研究方向为云计算安全架构、信息科技风险管理体系、金融科技风险。

  • 基金资助:
    国家重点研发计划[2018YFB0803503]

Model of Cloud Computing Security and Compliance Capability for Classified Protection of Cybersecurity 2.0

Zhenfeng ZHANG1, Zhiwen ZHANG1(), Ruichao WANG2   

  1. 1. Information Classified Security Protection Evaluation Center of the Ministry of Public Security, Beijing 100142, China
    2. Alibaba Cloud Computing Co., LTD., Beijing 100102, China
  • Received:2019-09-16 Online:2019-11-10 Published:2020-05-11

摘要:

文章基于网络安全等级保护基本要求,对云计算平台/系统的保护对象、安全措施及安全能力进行识别,构建网络安全等级保护2.0云计算安全合规模型,分析得出云计算平台/系统的安全技术能力。与网络安全等级保护2.0基本要求各测评项进行对比,可发现云平台/系统脆弱性,便于云服务商或云服务客户及时作出相应的安全加固,增强云计算平台/系统抵御风险的安全防护能力。

关键词: 网络安全等级保护, 云计算安全, 保护对象, 安全能力, 合规模型

Abstract:

Based on the baseline for classified protection of cybersecurity, this paper identified the classified protection object, safety measures and security capabilities of cloud computing platform/system, building the model of cloud computing security and compliance capability for classified protection of cybersecurity 2.0. The security technology capability of cloud computing platform/system can be obtained by comparing with each evaluation item of classified protection of cybersecurity, and the vulnerability of cloud platform/system can be found, which is convenient for cloud service providers and cloud service customers to make corresponding security reinforcement to enhance the security protection ability of cloud computing platform/system resist risk.

Key words: classified protection of cybersecurity, cloud computing security, classified protection object, security capability, compliance model

中图分类号: