论文部分内容阅读
做好信息系统的安全保障工作需要多少投资?许多信息系统的主管往往心中无数。同样的,科研单位和企业应该开发什么样的安全产品?信息安全专家应该如何对安全产品进行正确的评审?信息安全职能部门应该如何对信息系统的安全工作进行有效监督?这往往也很难说清楚。 这些问题如不解决,将导致国家信息安全科学技术水平和整体信息安全保护能力很难提高。为此,国家信息化领导小组决定加强信息安全保障工作,实行信息安全等级保护。这一重大决定,明确落实了《中华人民共和国计算机信息系统安全保护条例》中关于实行信息安全等级保护制度的有关规定。对信息系统实行等级保护是国家法定制度和基本国策,是开展信息安全保护工作的发展方向。实行信息安全等级保护的决定具有重大的现实和战略意义。 信息安全产品是信息系统等级保护的基础。因此,对信息安全产品进行等级认证就显得尤为重要,它将为信息系统安全建设提供重要的依据和切实保障。 本期CSO沙龙将和您一起探讨信息安全产品等级认证在等级保护中所发挥的作用。
How much investment is needed to ensure the security of your information system? Many information system directors tend to countless hearts. Similarly, what kind of security products should be developed by research institutes and enterprises? How should information security experts conduct a correct assessment of security products? How should information security functional departments effectively supervise the security of information systems? It is often hard to say clearly . If these problems are not solved, the level of science and technology in national information security and the overall capability of information security protection will be hard to be improved. To this end, the State Informatization Leading Group decided to strengthen information security and protection and implement information security protection. This major decision expressly implemented the relevant provisions of the “Regulations of the People’s Republic of China on the Protection of Computer Information System Security” regarding the implementation of the information security level protection system. The implementation of hierarchical protection of information systems is a national statutory system and a basic national policy and is the development direction for carrying out information security protection work. The decision to implement information security level protection is of great realistic and strategic significance. Information security products are the basis of information system level protection. Therefore, the level of information security products certification is particularly important, it will provide an important basis for information system security and effective protection. This issue of CSO Salon will work with you to explore the role of information security product level certification in rating protection.