信息安全研究 ›› 2022, Vol. 8 ›› Issue (1): 101-.

• 技术应用 • 上一篇    

综合性集团网络安全水平评价指标体系构建与实证研究

曹龙;吉梁;朱彤;   

  1. (中核核信信息技术(北京)有限公司 北京 100048

  • 出版日期:2022-01-09 发布日期:2022-01-07
  • 通讯作者: 曹龙 网络安全工程师.主要研究方向为网络安全与工控安全. caolong@cnnc.com.cn
  • 作者简介:曹龙 网络安全工程师.主要研究方向为网络安全与工控安全. caolong@cnnc.com.cn 吉梁 硕士,网络安全工程师.主要研究方向为网络安全与渗透测试. jiliang@cnnc.com.cn 朱彤 工学学士,高级工程师.主要研究方向为网络安全. zhutong@cnnc.com.cn

Construction and Empirical Research on Evaluation Index System of Comprehensive Group Cyber Security Level

  • Online:2022-01-09 Published:2022-01-07

摘要: 综合性集团往往涉及行业较多,旗下各行业网络安全水平参差不齐,网络安全水平统一评价工作经常难以开展.为解决这一问题,本文尝试站在综合性集团网络安全管理者的角度,分析了建立网络安全水平评价体系的意义、难点和思路,进而在已有的研究文献基础上,探索建立了跨行业网络安全3层指标体系及评价体系.通过在5家单位的试点应用,验证了指标体系、评价体系的合理性和可行性,并针对试点单位情况,提出了增进网络安全能力建设的意见,也为综合性集团的网络安全水平评价工作提供了参考.

关键词: 跨行业, 网络安全, 水平评价, 指标体系, 试点应用

Abstract: Comprehensive groups often involve many industries, and the cyber security level of each industry is uneven, so it is often difficult to carry out the unified evaluation of the cyber security level. To solve this problem, this article attempts to analyze the significance, difficulties and ideas of establishing a network security level evaluation system from the perspective of a comprehensive group network security manager. Furthermore, on the basis of the existing research literature, a three-tier index system and evaluation system for cross-industry cyber security has been explored and established. Through the pilot application in 5 units, the rationality and feasibility of the index system and evaluation system have been verified. It also puts forward suggestions to improve the cyber security capacity building based on the conditions of the pilot units, and also provides a reference for the evaluation of the cyber security level of comprehensive groups.

Key words: cross-industry, cyber security, level evaluation, index system, pilot application