欢迎来到天天文库
浏览记录
ID:58418945
大小:512.50 KB
页数:34页
时间:2020-05-11
《信息安全风评估规范.doc.doc》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、ICS35.040L80中华人民共和国国家标准GB/T20984—2007信息安全技术信息安全风险评估规范Informationsecuritytechnology—Riskassessmentspecificationforinformationsecurity2007-06-14发布2007-11-01实施中华人民共和国国家质量监督检验检疫总局发布中国国家标准化管理委员会GB/T20984—2007目次前言.............................................................................
2、....II引言................................................................................III1范围................................................................................12规范性引用文件......................................................................13术语和定义.....................................
3、.....................................14风险评估框架及流程..................................................................34.1风险要素关系......................................................................34.2风险分析原理......................................................................44.3实施流程...............
4、...........................................................45风险评估实施........................................................................55.1风险评估准备......................................................................55.2资产识别......................................................................
5、....75.3威胁识别..........................................................................95.4脆弱性识别.......................................................................115.5已有安全措施确认.................................................................125.6风险分析............................................
6、.............................125.7风险评估文档记录.................................................................146信息系统生命周期各阶段的风险评估...................................................156.1信息系统生命周期概述.............................................................156.2规划阶段的风险评估..............................
7、.................................156.3设计阶段的风险评估...............................................................156.4实施阶段的风险评估...............................................................166.5运行维护阶段的风险评估...............
此文档下载收益归作者所有