【24h】

On the buzzword 'security policy'

机译:流行语“安全策略”

获取原文
获取外文期刊封面目录资料

摘要

It is pointed out that, although the term 'security policy' is fundamental to computer security, its conflicting meanings have obscured important conceptual distinctions, especially where concerns other than confidentiality are involved. A clearer definition is needed to clarify routine technical discourse, facilitate resolution of key research issues, and establish the scope of security research and standardization efforts. The terms security policy objective, organization security policy, and automated security policy are proposed. These terms are based on simple generalizations of ideas that underlie the trusted computer system evaluation criteria (TCSEC). Yet, they describe a view of security that is more precise, more general, and different than 'confidentiality, integrity, and assured service'. Their usefulness in clarifying conceptual and terminological issues is illustrated through examples.
机译:需要指出的是,尽管“安全策略”一词对于计算机安全而言是必不可少的,但其相互矛盾的含义却掩盖了重要的概念区别,尤其是在涉及除机密性之外的其他方面。需要更清晰的定义来阐明常规技术讨论,促进关键研究问题的解决以及建立安全性研究和标准化工作的范围。提出了术语“安全策略目标”,“组织安全策略”和“自动安全策略”。这些术语基于对受信任计算机系统评估标准(TCSEC)的思想的简单概括。但是,它们所描述的安全性观点比“机密性,完整性和有保证的服务”更为精确,更笼统且与众不同。通过示例说明了它们在澄清概念和术语问题方面的有用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号