ҵϢƼоʵʩ
ë ϣҦ꣬ڣ
ժ Ҫ[ժ Ҫ]ҵݴе·մУһϢȫ¼ܵһҹšͨչϢƼǰֺԵΪҪҪܽISO 27001ISO 15408ISO 13335NISTչܡGB/T 209845˻߷Ҫϵͳ̷ʲࡢࡢߣϣƶҵ ڿơϢȫͨű (),ڡ2012(000)005 ҳ4
ؼʡ[ؼ]УϢƼ
0
2011412գģСũЭڿͻϢڵĴݱɾʹ۸ģ¸5 000ҷȫͣҵ¼18ҵŻָͬʱкϵͳ崻¼аȫ¹ʡÿϢй¶¼¶ҵڷչ滹ȱʧΪӴҵϢƼչȣ2009ӡҵϢƼչָҪҵСЧĻƣʵֶҵϢƼյʶ𡢼ͿơǷʶͼҪֶΣҲǷչҪɲ֡
1 ǰ
չӦ߱רҵԱͷ֮⣬ӦƶϢƼչԺϢƼշּǷչǰᡣ
1.1 ƶϢƼչ
οչչ̶ֳȣȡڱеķչԡһ£չԿɷΪȽء3ֲԡáķչԣٿչչմʱֻø߷գСͷաáȽķչԣӦöڿչմʱøߡзգܵͷաáءķչԣӦóչմʱߡСͷȫáϢƼչӦȫзչԵָ£ƶϢƼԾķչԡ翪չȫϢϵͳȫȼڲͬȼϢϵͳŲͬбϣΪһ־ķչԡ 1.2 ƶϢƼշּ
ҪijɹֵķյбݲͬķչԣȷԸߡСͲͬյĴҪǣߡСͷλҪƶּշּƶݶָ꣬ʧӰ췶ΧӰʱȣҲݰ붨ָ꣬ϢʲҪ̶ȡв̶ȡԳ̶ȵȣרҵġͷԷ籩ȷһЩָ꣬籾кϵͳȱѱϵͳ϶Ϊ߷ա
2
оùеķչҵʵڷĿչкܺõָ塣ķչISO 27001ISO 15408ISO 13335NIST SP800ϵеȡ 2.1 ISO 27001Ϣȫϵ
ISO 27001Ϣȫϵ(Information Security Management SystemsISMS)ȫձͬȨϢȫṩһҵϢȫչʵʵʩָϡISO 27001ͳ֯Ϣȫķ棬Ϣȫ롢Ϣȫ֯ʲԴȫͻȫͨźͲʿơϢϵͳȡάϢȫ¼ҵԹڵ11133ƴʩ[1]ISO 27001ͨPDCAģʽ(PlanDoCheckActPDCA)Ľ֯İȫڷУԲοISO 27001ἰ11133ƴʩģ塣 2.2 ISO 15408Ϣȫ
ISO 15408Ϣȫ(¼ơͨ)1999귢ģۺ(Ұȫֺо)ôŷ(Ӣ¹)67ļȫͬڡϢȫͨ(CC2.1)ISO/IEC 15408ͨΪ3֣һ֡һģͨ͡ĻͻԭйһģͼйصһЩܣڶ֡ȫҪա--ķʽ˰ȫҪ֡ȫ֤Ҫ
商业银行信息科技风险评估研究与实?- 百度文库



