信息安全研究 ›› 2021, Vol. 7 ›› Issue (8): 779-782.

• 技术应用 • 上一篇    下一篇

欧盟云安全认证计划的启示和借鉴

赵慧   

  1. (国家工业信息安全发展研究中心 北京 100040)
  • 出版日期:2021-08-12 发布日期:2021-08-16
  • 通讯作者: 赵慧
  • 作者简介:赵慧 硕士,高级工程师.主要研究方向为网络安全、工控安全、工业互联网安全政策、技术和产业. 93881309@qq.com

  • Online:2021-08-12 Published:2021-08-16

摘要: 2019年,欧盟出台《欧盟网络安全法》,推进了欧盟网络安全认证框架的建立和实施.在该框架下,专门成立特别工作组,研究起草《云服务网络安全认证计划(EUCS)》,于2020年底发布草案并公开征求意见.首先简要分析了计划草案的起草背景、依据、文本等基本情况;然后从利益相关方确定、安全保证级别划分、云计算服务分类等总结了该计划草案的要点内容;最后给出对我国加强云计算服务安全评估和认证的思考.

关键词: EUCS计划, 云计算, 云服务安全, 认证, 评估 

Abstract: The European Union has promulgated the Cybersecurity Act to promote the establishment and implementation of the EU cybersecurity certification Framework in 2019. As a part of the Framework, a special working group has been set up to work on EU Cybersecurity Certification Scheme for Cloud Services(EUCS). The EUCS candidate draft has been released for public comments at the end of 2020.This article first briefly analyzes the background, basis, text and other basic conditions of the draft. Then it sums up the main points of the draft from the determination of stakeholders, the classification of security assurance levels, and the classification of cloud computing services. Finally, it gives some thoughts on strengthening the security certification and assessment of cloud computing services in our country. 

Key words: EUCS scheme, cloud computing, cloud service security, certification, assessment