论文部分内容阅读
最新公布的《网络安全法》(二审稿)新增第25条对漏洞管理提出相应要求:“开展网络安全认证、检测、风险评估等活动,向社会发布系统漏洞、计算机病毒、网络攻击、网络侵入等网络安全信息,应当遵守国家有关规定。”这是针对当前漏洞管理和利用中存在的诸多问题而作出的政策表态。本期专题围绕这一问题,从法律、行业、标准等几个层面进行展开,希望可以给漏洞管控提供有益的参考。
The newly published “Network Security Law” (second review draft) added Article 25 of the vulnerability management requirements: “to carry out network security certification, testing, risk assessment and other activities, to the community release system vulnerabilities, computer viruses, cyber attacks , Network intrusions and other cybersecurity information, it should abide by the relevant provisions of the State. ”This is a policy statement made in response to the many problems that exist in current vulnerability management and utilization. This issue focuses on this issue, from the legal, industry, standards and other aspects of the start, I hope we can provide a useful reference for the control of loopholes.