首页|电力信息系统安全基线测试方法研究

电力信息系统安全基线测试方法研究

扫码查看
在综合考察了电力信息系统网络布局和安全现状的基础上结合IS027001国际标准提出了基于安全基线的电力企业信息系统安全框架.该框架将电力信息系统面临的复杂环境分成网络设备、主机、数据库、中间件和应用系统几个关键部分,着眼于关键部分分别设定了安全基线从而消除大部分安全隐患.整个框架强调了系统上线后的日常维护和人员活动在整个安全体系中的重要性,将原来仅从单一的计算机网络角度出发的安全措施拓展成为技术加管理的安全框架使安全措施更加全面.
Baseline Test Technology for Electric Power Information System Security
Based on the comprehensive inspection of electric power information system network layout and security status quo,and combined with IS027001 international standards,this paper formulates the electric power enterprise information system security framework bsed on security baseline.The framework divides the complex environment of electric power information system into several key parts:network devices,the host,database,middleware and application system.With a focus on the key parts,the safe security baselines are set up respectively in order to eliminate most of the potential security hazards.The framework highlights the importance of online system daily maintenance and operator activities in the whole security system,achieving more comprehensive security measures by developing the original security measure only from the perspective of a single computer network into a technology-management integrated security framework.

electric power information systeminformation securitybaseline testsecurity framework

陈亮、殷博、林永峰、张国强

展开 >

国网天津市电力公司电力科学研究院,天津 300384

国网天津市电力公司,天津 300010

电力信息系统 信息安全 基线测试 安全框架

2014

华东电力
华东电力试验研究院有限公司

华东电力

CSTPCD
影响因子:0.551
ISSN:1001-9529
年,卷(期):2014.42(5)
  • 3
  • 11