Guide for Security-Focused Configuration Management of Information Systems: The National Institute of Standards and Technology Special Publication 800-128
暫譯: 資訊系統安全導向配置管理指南:美國國家標準與技術研究所特別出版物 800-128

Arnold Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, Dennis Bailey

  • 出版商: CreateSpace Independ
  • 出版日期: 2012-07-02
  • 售價: $880
  • 貴賓價: 9.5$836
  • 語言: 英文
  • 頁數: 94
  • 裝訂: Paperback
  • ISBN: 1478180196
  • ISBN-13: 9781478180197
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

The purpose of the National Institute of Standards and Technology Special Publication 800-128, Guide for Security-Focused Configuration Management of Information Systems, is to provide guidelines for organizations responsible for managing and administering the security of federal information systems and associated environments of operation. Configuration management concepts and principles described in NIST SP 800-128, provide supporting information for NIST SP 800-53, Recommended Security Controls for Federal Information Systems and Organizations. NIST SP 800-128 assumes that information security is an integral part of an organization’s overall configuration management. The focus of this document is on implementation of the information system security aspects of configuration management, and as such the term security-focused configuration management (SecCM) is used to emphasize the concentration on information security. In addition to the fundamental concepts associated with SecCM, the process of applying SecCM practices to information systems is described. The goal of SecCM activities is to manage and monitor the configurations of information systems to achieve adequate security and minimize organizational risk while supporting the desired business functionality and services.~

商品描述(中文翻譯)

國家標準與技術研究院特別出版物 800-128《資訊系統安全導向配置管理指南》的目的是為負責管理和維護聯邦資訊系統及其相關操作環境安全的組織提供指導。NIST SP 800-128 中描述的配置管理概念和原則,為 NIST SP 800-53《聯邦資訊系統和組織的建議安全控制》提供了支持性資訊。NIST SP 800-128 假設資訊安全是組織整體配置管理的不可或缺的一部分。本文件的重點在於實施配置管理的資訊系統安全方面,因此使用了「安全導向配置管理」(SecCM)這一術語,以強調對資訊安全的重視。除了與 SecCM 相關的基本概念外,還描述了將 SecCM 實踐應用於資訊系統的過程。SecCM 活動的目標是管理和監控資訊系統的配置,以實現足夠的安全性並最小化組織風險,同時支持所需的業務功能和服務。