信息安全研究 ›› 2020, Vol. 6 ›› Issue (11): 0-0.

• 学术论文 •    

云计算平台安全能力评估体系和评估指标研究

贺海,刘海峰,成金爱   

  1. 北京信息安全测评中心
  • 收稿日期:2020-11-08 出版日期:2020-11-09 发布日期:2020-11-11
  • 通讯作者: 贺海

Research on Evaluation System and Index of Cloud Computing Platform Security Capability

  • Received:2020-11-08 Online:2020-11-09 Published:2020-11-11

摘要: 云计算平台作为提供云服务的基础性支撑平台,在承担着重要的安全功能和无限的数据价值的同时,也意味着云计算平台已成为主要的攻击目标而面临着巨大的安全风险.如何评估云计算平台的安全能力是当前迫切需要解决的重要课题.与传统信息系统相比,云计算平台有其自身的特点和特殊性,传统的测评方法不能准确评估云计算平台的安全能力,目前也尚未建立可行的评估云计算平台安全能力的评估体系.本文基于实践经验的总结,从动态安全评估、性能效率评估、静态合规核查3个层面构建了云计算平台安全能力评估体系,构建了云计算平台安全能力评估体系,设计了科学合理的评估指标和评估方法,可以全方位检验云计算平台的实际安全能力,可以横向比较各云计算平台的实际安全能力,可以支撑测评机构开展对云计算平台安全能力的评估工作,也有利于云服务商针对风险问题提升安全服务能力.

关键词: 云计算平台, 安全能力, 评估体系, 评估指标, 评估方法, IaaS

Abstract: As the basic support platform for providing cloud services, cloud computing platform not only bears important security functions and unlimited data value, but also means that cloud computing platform has become the main target of attack and faces huge security risks. How to evaluate the security capability of cloud computing platform is an important issue that needs to be solved urgently. Compared with the traditional information system, the cloud computing platform has its own characteristics and particularity. The traditional evaluation methods can not accurately evaluate the security capability of the cloud computing platform. At present, there is no feasible evaluation system to evaluate the security capability of the cloud computing platform. Based on the summary of practical experience, this paper constructs the security capability evaluation system of cloud computing platform from three aspects of dynamic security evaluation, performance efficiency evaluation and static compliance verification, constructs the security capability evaluation system of cloud computing platform, designs scientific and reasonable evaluation indexes and methods, which can comprehensively test the actual security capability of cloud computing platform and can horizontally compare each other The actual security capability of the cloud computing platform can support the assessment institutions to carry out the assessment of the security capability of the cloud computing platform, and also help the cloud service providers to improve the security service capability against risk issues.

Key words: cloud computing platform, security capability, Evaluation system, evaluating indicator , Evaluation method, IaaS