ANSI INCITS ISO IEC TR 13335-5-2001 Information Technology - Guidelines for the Management of IT Security - Part 5 Management Guidance on Network Security (TECHNICAL REPORT).pdf
《ANSI INCITS ISO IEC TR 13335-5-2001 Information Technology - Guidelines for the Management of IT Security - Part 5 Management Guidance on Network Security (TECHNICAL REPORT).pdf》由会员分享,可在线阅读,更多相关《ANSI INCITS ISO IEC TR 13335-5-2001 Information Technology - Guidelines for the Management of IT Security - Part 5 Management Guidance on Network Security (TECHNICAL REPORT).pdf(40页珍藏版)》请在麦多课文档分享上搜索。
1、 INCITS/ISO/IEC TR 13335-5-2001 (R2007) (ISO/IEC TR 13335-5:2001, IDT) Information Technology - Guidelines for the Management of IT Security - Part 5: Management Guidance on Network Security (TECHNICAL REPORT) INCITS/ISO/IEC TR 13335-5-2001 (R2007) PDF disclaimer This PDF file may contain embedded t
2、ypefaces. In accordance with Adobes licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, parties accept therein the responsibility of not in
3、fringing Adobes licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were o
4、ptimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. Registered by INCITS (InterNational Committee for Informa
5、tion Technology Standards) as an American National Standard. Date of Registration: 12/31/2006 Published by American National Standards Institute, 25 West 43rd Street, New York, New York 10036 Copyright 2006 by Information Technology Industry Council (ITI). All rights reserved. These materials are su
6、bject to copyright claims of International Standardization Organization (ISO), International Electrotechnical Commission (IEC), American National Standards Institute (ANSI), and Information Technology Industry Council (ITI). Not for resale. No part of this publication may be reproduced in any form,
7、including an electronic retrieval system, without the prior written permission of ITI. All requests pertaining to this standard should be submitted to ITI, 1101 K Street NW, Suite 610, Washington DC 20005. Printed in the United States of America ii ITIC 2006 All rights reserved Reference numberISO/I
8、EC TR 13335-5:2001(E)ISO/IEC 2001TECHNICAL REPORT ISO/IECTR13335-5First edition2001-11-01Information technology Guidelines for the management of IT Security Part 5: Management guidance on network securityTechnologies de linformation Lignes directrices pour la gestion de scurit IT Partie 5: Guide pou
9、r la gestion de scurit du rseau ISO/IEC TR 13335-5:2001(E) PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobes licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the
10、computer performing the editing. In downloading this file, parties accept therein the responsibility of not infringing Adobes licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to
11、create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform
12、 the Central Secretariat at the address given below. ISO/IEC 2001 All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from
13、 either ISO at the address below or ISOs member body in the country of the requester. ISO copyright office Case postale 56 CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 749 09 47 E-mail copyrightiso.ch Web www.iso.ch Printed in Switzerland ii ISO/IEC 2001 All rights reservedISO/IEC TR 13335-5
14、:2001(E) ISO/IEC 2001 All rights reserved iiiTABLE OF CONTENTSForewordvIntroduction vi1.SCOPE12.REFERENCES13.DEFINITION 24.ABBREVIATION 25.STRUCTUR 26.AIM37.OVERVIEW37.1Background37.2Identification Process38REVIEW CORPORATE IT SECURITY POLICY REQUIREMENTS69REVIEW NETWORK ARCHITECTURES AND APPLICATIO
15、NS69.1Introductio 69.2Types of Network79.3Network Protocol 89.4Network Application 89.5Other Consideration 810IDENTIFY TYPES OF NETWORK CONNECTION 811 REVIEW NETWORKING CHARACTERISTICS AND RELATED TRUSTRELATIONSHIPS1111.1Network Characteristic 1111.2Trust Relationship 12ISO/IEC TR 13335-5:2001(E) iv
16、 ISO/IEC 2001 All rights reserved12DETERMINE THE TYPES OF SECURITY RISK1313IDENTIFY APPROPRIATE POTENTIAL SAFEGUARD AREAS1713.1Introductio 1713.2Secure Service Managemen 1813.2.1Introductio 1813.2.2Security Operating Procedures1913.2.3Security Compliance Checking1913.2.4 Security Conditions For Conn
17、ectio 1913.2.5Documented Security Conditions for Users of Network Services2013.2.6Incident Handlin 2013.3Identification and Authenticatio 2013.3.1Introductio 2013.3.2Remote Log-i 2013.3.3Authentication Enhancement 2113.3.4Remote System Identificatio 2113.3.5Secure Single Sign-o 2213.4Audit Trail 221
18、3.5Intrusion Detectio 2313.6Protection Against Malicious Code2413.7Network Security Managemen 2413.8Security Gateway 2513.9Data Confidentiality Over Networks2613.10Data Integrity Over Network 2613.1 Non-Repudiatio 2713.12 Virtual Private Network 2813.13Business Continuity/Disaster Recovery2814DOCUME
19、NT AND REVIEW SECURITY ARCHITECTURE OPTIONS2915 PREPARE FOR THE ALLOCATION OF SAFEGUARD SELECTION,DESIGN, IMPLEMENTATION AND MAINTENANCE2916SUMMARY29Bibliography 31ISO/IEC TR 13335-5:2001(E) ISO/IEC 2001 All rights reserved vForeword ISO (the International Organization for Standardization) and IEC (
20、the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with part
21、icular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of information technology, ISO and IEC have esta
22、blished a joint technical committee, ISO/IEC JTC 1. International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 3. The main task of the joint technical committee is to prepare International Standards. Draft International Standards adopted by the joint techn
23、ical committee are circulated to national bodies for voting. Publication as an International Standard requires approval by at least 75 % of the national bodies casting a vote. In exceptional circumstances, the joint technical committee may propose the publication of a Technical Report of one of the
24、following types: type 1, when the required support cannot be obtained for the publication of an International Standard, despite repeated efforts; type 2, when the subject is still under technical development or where for any other reason there is the future but not immediate possibility of an agreem
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ANSIINCITSISOIECTR1333552001INFORMATIONTECHNOLOGYGUIDELINESFORTHEMANAGEMENTOFITSECURITYPART5MANAGEMENTGUIDANCEONNETWORKSECURITYTECHNICALREPORTPDF

链接地址:http://www.mydoc123.com/p-436610.html