您的位置:首页 > 职场人生

信息安全方针、标准、指导方针、流程的关系

2009-01-13 21:12 357 查看
一个很好的例子,说明信息安全方针、标准、指导方针、流程的关系:
A corporation’s security
policy indicates that confidential information should be properly protected. It states
the issue in very broad and general terms. A supporting standard mandates that all
customer information held in databases must be encrypted with the Advanced Encryption
Standard (AES) algorithm while it is stored and that it cannot be transmitted over
the Internet unless IPSec encryption technology is used. The standard indicates what
type of protection is required and provides another level of granularity and explanation.
The supporting procedures explain exactly how to implement the AES and IPSec
technologies, and the guidelines cover how to handle cases when data is accidentally
corrupted or compromised during transmission. All of these work together to provide
a company with a security structure.
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签:  职场 安全 休闲