信息网络安全 ›› 2020, Vol. 20 ›› Issue (3): 1-8.doi: 10.3969/j.issn.1671-1122.2020.03.001

• 等级保护 • 上一篇    下一篇

网络安全等级保护测评中结论产生的定量计算方法研究

马力()   

  1. 公安部信息安全等级保护评估中心,北京 100142
  • 收稿日期:2019-12-15 出版日期:2020-03-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:马力(1963—),男,江苏,副研究员,硕士,主要研究方向为信息技术、网络安全、等级保护。

Research on the Quantitative Calculation Method Resulting from the Conclusions in the Assessment of Classified Protection of Cybersecurity

MA Li()   

  1. Information Classified Security Protection Evaluation Center of the Ministry of Public Security,Beijing 100142, China
  • Received:2019-12-15 Online:2020-03-10 Published:2020-05-11

摘要:

国家网络安全等级保护标准结构和内容的变化,尤其是与等级测评环节有关的标准的变化,带来了等级测评产生结论的变化,而如何通过定量计算方法合理准确地反映等级保护对象的安全保护状况和具有的安全保护能力,一直是安全等级测评探索的方向。文章研究分析了等级测评结论的产生原理,提出了基于测评指标和测评对象的定量分析方法,通过实例证明测评指标和测评对象的权重赋值直接影响定量分析的最终结果。为了获得更加准确和具有说服力的测评结论,需要在定量计算方法中探索测评指标和测评对象的合理权重赋值方法。

关键词: 等级保护对象, 安全等级测评, 测评指标, 测评对象

Abstract:

The change of the structure and content of the national classified protection of cybersecurity standard, especially the standard change related to the assessment of classified protection of cybersecurity, brought about the change of the conclusion of the assessment of classified protection of cybersecurity, and how to accurately reflect the security protection status and the security protection ability of the level protection object by quantitative calculation method. It has always been the direction of exploration in the assessment of classified protection of cybersecurity, This paper studies and analyzes the principle of the production of the evaluation conclusionsinclassified protection assessment, and puts forward the quantitative analysis methodbasedon the assessment requirements and the assessment objects respectively, and shows through the example that the weight assignment of the assessment requirements and theassessment objects directly affects the final result of quantitative analysis. In order to obtain more accurate and persuasive evaluation conclusions, it is necessary to explore the reasonable weighting method of the assessment requirements and the assessment objects in the quantitative calculation method.

Key words: classified protection object, classified protection assessment, assessment requirements, assessment objects

中图分类号: