论文部分内容阅读
网络安全审查是对关系国家安全和社会稳定信息系统中,使用的信息技术产品与服务进行测试评估、监测分析、持续监督的过程。云计算作为政府部门和重点行业采用的一种重要服务,其安全性也在审查范围内。因此,加强为政府部门和重点行业提供云服务的云服务商的审查,是保障云计算平台安全和国家信息安全的重要手段。云服务安全国家标准将为云服务安全审查提供重要依据。美国早在2009年就开始了联邦政府使用云计算的安全评估与授权的研究,并于2011年12月8日正式发布了《云计算环境中信息系统的安全授权》,建立了联邦政府风险和授权管理项目(FedRAMP),规定了对云计算安全控制措施的要
Cybersecurity review is a process of testing and evaluating, monitoring and analyzing, and continuously monitoring the information technology products and services used in relation to the national security and social stability information system. As an important service adopted by government agencies and key industries, cloud computing is also under scrutiny. Therefore, to strengthen the review of cloud service providers that provide cloud services to government departments and key industries is an important means to ensure the safety of cloud computing platforms and national information security. National standards for cloud services security will provide an important basis for cloud services security review. As early as 2009, the United States began research on the use of cloud computing for security assessment and authorization by the federal government and officially released “Security Authorization for Information Systems in Cloud Computing Environment” on December 8, 2011, establishing the federal government’s risk and Mandate Management Project (FedRAMP), which sets out the requirements for cloud computing security controls