Journal of Information Security Research ›› 2020, Vol. 6 ›› Issue (12): 1139-1144.

Previous Articles    

Research on Life Cycle Security Management from the Perspective of Information System Builders

  

  • Received:2020-12-07 Online:2020-12-08 Published:2020-12-08

信息系统建设者视角下生命周期安全管理研究

朱林1,陆明2   

  1. 1. 中国信息安全审查技术与认证中心
    2. 北京亮点软测科技有限公司
  • 通讯作者: 朱林
  • 作者简介:朱林 助理研究员,中国网络安全审查技术与认证中心,主要研究方向为信息安全政策与法规标准体系研究、信息系统安全管理研究、信息安全技术研究. 10202251@qq.com 陆明 硕士,北京亮点软测科技有限公司总经理,主要研究方向为软件安全测试、软件质量测试、软件安全管理、软件质量管理. lm@lumder.com

Abstract: This paper analyzes the security management activities of the information system life cycle, and from the perspective of the information system builders, combined with the PDCA model and system security engineering ideas, and proposes a continuous optimization closed-loop control model for information system security management, and explain the safety management activities of the builders at each stage of the life cycle of the information system, and realize the safety management at all stages of the life cycle of the information system by planning safety goals, designing safety systems, implementing safety development, verifying safety goals, and continuing to maintain safety. The management objects, management activities and management objectives of each stage will ultimately provide information system builders with ideas for information system safety management throughout the life cycle.

Key words: information system, safety goal, safety system, full life cycle, security management, security assurance

摘要: 本文通过分析信息系统生命周期的安全管理活动,从信息系统建设者视角出发,结合PDCA模型和系统安全工程思路提出了针对信息系统安全管理的持续优化闭环控制模型,阐述信息系统全生命周期各阶段建设者的安全管理活动,通过规划安全目标、设计安全体系、落实安全开发、验证安全目标、持续维护安全等工作实现信息系统全生命周期各阶段的安全管理,明确每个阶段的管理对象、管理活动和管理目标,最终为信息系统建设者提供信息系统全生命周期安全管理思路.

关键词: 信息系统, 安全目标, 安全体系, 全生命周期, 安全管理, 安全保障