【24h】

Developing an enterprise information security policy

机译:制定企业信息安全策略

获取原文
获取外文期刊封面目录资料

摘要

The University of Pittsburgh is at the midpoint of a three-year strategic plan focused on information technology. Our strategic direction is based on a tiered model consisting of these layers: network infrastructure, middleware, Web infrastructure, and the set of applications and services that can be provided to our user community. As applications and services become increasingly more complex, there is a greater potential for security breaches that must be adequately addressed.The ability for students and faculty to share data and collaborate on projects is of utmost importance to any higher education institution. A large, multidisciplinary institution such as the University of Pittsburgh must be able to find an effective balance between the need to provide people in the local, national, and international communities with access to information and the need to protect sensitive information from unauthorized access and misuse.The subject of information security has received a great deal of attentionwithin academia before and after the events of September 11, 2001. Federal regulations such as the HIPAA legislation protecting patient data, the USA PATRIOT Act, and the Digital Millennium Copyright Act all have significant impact. The complexities involved in developing adequate security plans have resulted in the development of the ISO 17799 standard, used widely in security plan development.A University-wide security plan is under development that, when completed, will address security at all levels. This comprehensive security plan will cover policies, business practice changes, and user awareness concerns. This presentation focuses on the process that is underway to identify security issues and to design and implement a comprehensive security plan that maintains an open academic environment and fully addresses relevant legislation and best practice models.
机译:匹兹堡大学正处于针对信息技术的三年战略计划的中期。我们的战略方向是基于由以下几层组成的分层模型:网络基础结构,中间件,Web基础结构以及可以提供给用户社区的一组应用程序和服务。随着应用程序和服务变得越来越复杂,存在更大的潜在安全隐患,必须予以适当解决。学生和教职员工共享数据以及在项目上进行协作的能力对任何高等教育机构都至关重要。像匹兹堡大学这样的大型跨学科机构必须能够在为本地,国家和国际社区的人们提供信息访问的需求与保护敏感信息免遭未经授权的访问和滥用的需求之间找到有效的平衡。在2001年9月11日事件前后,信息安全性问题在学术界引起了广泛关注。联邦法规,例如保护患者数据的HIPAA立法,《美国爱国者法案》和《数字千年版权法案》都具有重要意义。影响。制定适当的安全计划所涉及的复杂性导致了ISO 17799标准的开发,该标准被广泛用于安全计划的开发中。正在开发一项大学范围的安全计划,该计划完成后将解决所有级别的安全问题。这份全面的安全计划将涵盖策略,业务实践更改以及用户意识方面的问题。本演示文稿重点介绍了正在进行的过程,这些过程正在确定安全问题并设计和实施一个综合的安全计划,该计划将维护开放的学术环境,并全面解决相关的立法和最佳实践模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号