1 / 80
文档名称:

(International Standard - En - Management Systems - Information Security) Iso Iec 13335-4 2000.pdf

格式:pdf   页数:80
下载后只包含 1 个 PDF 格式的文档,没有任何的图纸或源代码,查看文件列表

如果您已付费下载过本站文档,您可以点这里二次下载

(International Standard - En - Management Systems - Information Security) Iso Iec 13335-4 2000.pdf

上传人:kuo08091 2014/9/17 文件大小:0 KB

下载得到文件列表

(International Standard - En - Management Systems - Information Security) Iso Iec 13335-4 2000.pdf

文档介绍

文档介绍:1

ISO/IEC TR 13335-4
First edition 2000-03-01







Information technology – Guidelines for the
management of IT security –
Part 4: Selection of safeguards
2
Table of Contents

Foreword
Introduction

1 Scope

2 References

3 Definitions

4 Aim

5 Overview

6 Introduction to Safeguard Selection and the Concept of Baseline Security

7 Basic Assessments
Identification of the Type of IT System
Identification of Physical/Environmental Conditions
Assessment of Existing/Planned Safeguards

8 Safeguards
and Physical Safeguards
IT Security Management and Policies
pliance Checking
Incident Handling
Personnel
Operational Issues
Business Continuity Planning
Physical Security
IT System Specific Safeguards
Identification and Authentication (I&A)
Logical Access Control and Audit
Protection against Malicious Code
Management
Cryptography

9 Baseline Approach: Selection of Safeguards According to the Type of IT System
Generally Applicable Safeguards
IT System Specific Safeguards

10 Selection of Safeguards According to Security Concerns and Threats
Assessment of Security Concerns
Loss of confidentiality
Loss of integrity
Loss of availability
Loss of accountability
Loss of authenticity
Loss of reliability
Safeguards for Confidentiality
Eavesdropping
ic radiation
Malicious code
3
Masquerading of user identity
Misrouting/re-routing of messages
Software failure
Theft
Unauthorized access puters, data, services and applications
Unauthorized access to storage media
Safeguards for Integrity
Deterioration of storage media
Maintenance error
Malicious code
Masquerading of user id