文档介绍:1
ISO/IEC TR 13335-4
First edition 2000-03-01
Information technology – Guidelines for the
management of IT security –
Part 4: Selection of safeguards
2
Table of Contents
Foreword
Introduction
1 Scope
2 References
3 Definitions
4 Aim
5 Overview
6 Introduction to Safeguard Selection and the Concept of Baseline Security
7 Basic Assessments
Identification of the Type of IT System
Identification of Physical/Environmental Conditions
Assessment of Existing/Planned Safeguards
8 Safeguards
and Physical Safeguards
IT Security Management and Policies
pliance Checking
Incident Handling
Personnel
Operational Issues
Business Continuity Planning
Physical Security
IT System Specific Safeguards
Identification and Authentication (I&A)
Logical Access Control and Audit
Protection against Malicious Code
Management
Cryptography
9 Baseline Approach: Selection of Safeguards According to the Type of IT System
Generally Applicable Safeguards
IT System Specific Safeguards
10 Selection of Safeguards According to Security Concerns and Threats
Assessment of Security Concerns
Loss of confidentiality
Loss of integrity
Loss of availability
Loss of accountability
Loss of authenticity
Loss of reliability
Safeguards for Confidentiality
Eavesdropping
ic radiation
Malicious code
3
Masquerading of user identity
Misrouting/re-routing of messages
Software failure
Theft
Unauthorized access puters, data, services and applications
Unauthorized access to storage media
Safeguards for Integrity
Deterioration of storage media
Maintenance error
Malicious code
Masquerading of user id