ISO IEC 21827-2008 Information technology - Security techniques - Systems Security Engineering - Capability Maturity Model? (SSE-CMM?)《信息技术 安全技术 系统安全工程 能力成熟模型(S.pdf
《ISO IEC 21827-2008 Information technology - Security techniques - Systems Security Engineering - Capability Maturity Model? (SSE-CMM?)《信息技术 安全技术 系统安全工程 能力成熟模型(S.pdf》由会员分享,可在线阅读,更多相关《ISO IEC 21827-2008 Information technology - Security techniques - Systems Security Engineering - Capability Maturity Model? (SSE-CMM?)《信息技术 安全技术 系统安全工程 能力成熟模型(S.pdf(154页珍藏版)》请在麦多课文档分享上搜索。
1、 Reference number ISO/IEC 21827:2008(E) ISO/IEC 2008INTERNATIONAL STANDARD ISO/IEC 21827 Second edition 2008-10-15 Information technology Security techniques Systems Security Engineering Capability Maturity Model (SSE-CMM) Technologies de linformation Techniques de scurit Ingnierie de scurit systme
2、Modle de maturit de capacit (SSE-CMM) ISO/IEC 21827:2008(E) PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobes licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the
3、 computer performing the editing. In downloading this file, parties accept therein the responsibility of not infringing Adobes licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to
4、 create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please infor
5、m the Central Secretariat at the address given below. COPYRIGHT PROTECTED DOCUMENT ISO/IEC 2008 All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, with
6、out permission in writing from either ISO at the address below or ISOs member body in the country of the requester. ISO copyright office Case postale 56 CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 749 09 47 E-mail copyrightiso.org Web www.iso.org Published in Switzerland ii ISO/IEC 2008 All
7、 rights reservedISO/IEC 21827:2008(E) ISO/IEC 2008 All rights reserved iii Contents Page Foreword. v 0 Introduction vi 1 Scope . 1 2 Normative references . 1 3 Terms and definitions. 2 4 Background . 6 4.1 Reason for Development . 7 4.2 The Importance of Security Engineering 7 4.3 Consensus. 7 5 Str
8、ucture of the Document 8 6 Model Architecture . 8 6.1 Security Engineering 8 6.2 Security Engineering Process Overview 11 6.3 SSE-CMM Architecture Description .14 6.4 Summary Chart . 22 7 Security Base Practices . 23 7.1 PA01 Administer Security Controls 24 7.2 PA02 - Assess Impact. 28 7.3 PA03 - As
9、sess Security Risk . 32 7.4 PA04 - Assess Threat . 36 7.5 PA05 - Assess Vulnerability 39 7.6 PA06 - Build Assurance Argument . 43 7.7 PA07 - Coordinate Security . 46 7.8 PA08 - Monitor Security Posture. 49 7.9 PA09 - Provide Security Input . 54 7.10 PA10 - Specify Security Needs 59 7.11 PA11 - Verif
10、y and Validate Security 63 Annex A (normative) Generic Practices. 67 Annex B (normative) Project and Organizational Base Practices. 68 B.1 General. 68 B.2 General Security Considerations 68 B.3 PA12 - Ensure Quality 69 B.4 PA13 - Manage Configurations 74 B.5 PA14 - Manage Project Risks 78 B.6 PA15 -
11、 Monitor and Control Technical Effort. 82 B.7 PA16 - Plan Technical Effort 86 B.8 PA17 - Define Organizations Systems Engineering Process 92 B.9 PA18 - Improve Organizations Systems Engineering Processes. 96 B.10 PA19 - Manage Product Line Evolution99 B.11 PA20 - Manage Systems Engineering Support E
12、nvironment. 102 B.12 PA21 - Provide Ongoing Skills and Knowledge 106 B.13 PA22 - Coordinate with Suppliers . 112 Annex C (informative) Capability Maturity Model Concepts 117 C.1 General. 117 C.2 Process Improvement 117 C.3 Expected Results 118 ISO/IEC 21827:2008(E) iv ISO/IEC 2008 All rights reserve
13、dC.4 Common Misunderstandings. 118 C.5 Key Concepts 120 Annex D (informative) Generic Practices . 124 D.1 General . 124 D.2 Capability Level 1 - Performed Informally 125 D.3 Capability Level 2 - Planned and Tracked 126 D.4 Capability Level 3 - Well Defined. 132 D.5 Capability Level 4 - Quantitativel
14、y Controlled 137 D.6 Capability Level 5 - Continuously Improving. 139 Bibliography . 142 ISO/IEC 21827:2008(E) ISO/IEC 2008 All rights reserved v Foreword ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for
15、worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collabora
16、te in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1. International Standards are
17、 drafted in accordance with the rules given in the ISO/IEC Directives, Part 2. The main task of the joint technical committee is to prepare International Standards. Draft International Standards adopted by the joint technical committee are circulated to national bodies for voting. Publication as an
18、International Standard requires approval by at least 75 % of the national bodies casting a vote. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent righ
19、ts. ISO/IEC 21827 was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology, Subcommittee SC 27, IT Security techniques. In addition, alignment is being maintained with the publicly available System Security Engineering - Capability Maturity Model 1)(SSE-CMM) Version 3, publish
20、ed by the International Systems Security Engineering Association (ISSEA) as a Publicly Available Specification. This second edition cancels and replaces the first edition (ISO/IEC 21827:2002), which has been technically revised. SSE-CMM includes excerpts from “A Systems Engineering Capability Maturi
21、ty Model (SE-CMM), Version 1.1”, CMU/SEI95-MM-003, Copyright 1995 by Carnegie Mellon University. SE-CMM is a collaborative effort of Hughes Space and Communications, Hughes Telecommunications and Space, Lockheed Martin, Software Engineering Institute, Software Productivity Consortium, and Texas Inst
22、ruments Incorporated. Neither Carnegie Mellon University nor the Software Engineering Institute directly or indirectly endorse SSE-CMM or ISO/IEC 21827. 1) CMM and Capability Maturity Model are Service Marks of Carnegie Mellon University NOT-FOR-PROFIT CORPORATION PENNSYLVANIA, 5000 Forbes Avenue, P
23、ittsburgh, PA 15213, USA. ISO/IEC 21827:2008(E) vi ISO/IEC 2008 All rights reserved0 Introduction 0.1 General A wide variety of organizations practice security engineering in the development of computer programs, whether as operating systems software, security managing and enforcing functions, softw
24、are, middleware or applications programs. Appropriate methods and practices are therefore required by product developers, service providers, system integrators, system administrators, and even security specialists. Some of these organizations deal with high-level issues (e.g., ones dealing with oper
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ISOIEC218272008INFORMATIONTECHNOLOGYSECURITYTECHNIQUESSYSTEMSSECURITYENGINEERINGCAPABILITYMATURITYMODELSSECMM

链接地址:http://www.mydoc123.com/p-1257026.html