王晟, 赵建福, 李超峰, et al. Implementation of a sustainable security operation system[J]. 2020, 33(12): 37-41. DOI: 10.13992/j.cnki.tetas.2020.12.008.
持续化网络安全运营体系研究
摘要
当前网络安全指导思想从合规交付向能力输送转变
传统安全运维向持续化安全运营转变。安全运营是传统安全的集中和升华
在安全运营基础上
通过人、设备、数据和流程的有机结合
通过主动探测和动态防御
持续输出安全价值
解决安全风险
保证各类业务的实时安全稳定运行。本文从网络安全运营角度出发
详细阐述了网络安全运营管理体系的设计思想、基本框架、管理流程和流程间的关系。
Abstract
At present
the guiding ideology of network security has changed from compliance delivery to capability delivery
and traditional security operation and maintenance has changed to security operation. Security operation is the centralization and sublimation of traditional security. On the basis of security operation and maintenance
through the organic combination of people
equipment
data and processes
through active detection and dynamic defense
security value is continuously output
resolve security risks and ensure real-time secure and stable operation of various services. Starting from the current situation of security operation
this paper expounds in detail the design idea
basic framework
management process and the relationship between processes of the network security operation management system.