T/ISC-0011-2021
I
目 次
前 言
.................................................................................................................................................................
II
引 言
...............................................................................................................................................................
III
1 范围
................................................
...................................................................................................................
1
2 规范性引用文件
...............................................................................................................................................
1
3 术语和定义
..............................................................................................................................
.........................
1
4 概述
...................................................................................................................................................................
2
4.1 评估原则
...................................................................................................................................................
3
4.2 评估实施方法
...........................................................................................................................................
3
4.3 评估实施过程
...........................................................................................................................................
3
5 数据安全治理能力总体要求
...........................................................................................................................
4
6 评估等级
............
...............................................................................................................................................
4
6.1 第一级:基础级
.......................................................................................................................................
4
6.2 第二级:优秀级
....................................................................................................
...................................
4
6.3 第三级:先进级
.......................................................................................................................................
5
7 数据安全战略
...................................................................................................................................................
5
7.1 数据安全规划
......................................................
.....................................................................................
5
7.2 机构人员管理
...........................................................................................................................................
7
8 数据全生命周期安全
.....................................................................................................................................
10
8.1 数据采集安全
...........
..............................................................................................................................
10
8.2 数据传输安全
.........................................................................................................................................
12
8.3 存储安全
.....................................................................................................................
............................
15
8.4 数据备份与恢复
.....................................................................................................................................
17
8.5 使用安全
.................................................................................................................................................
19
8.6 数据处理环境安全
............................................................
.....................................................................
21
8.7 数据内部共享安全
.................................................................................................................................
23
8.8 数据外部共享安全
.................................................................................................................................
25
8.9 数据销毁安全
.........................................................................................................................................
28
9 基础安全
.........................................................................................................................................................
30
9.1 数据分类分级
................................................................................................................................
.........
30
9.2 合规管理
.................................................................................................................................................
32
9.3 合作方管理
.............................................................................................................................................
34
9.4 监控审计
.................................................................................................................................................
37
9.5 鉴别与访问
.............................................................................................................................................
39
9.6 风险和需求分析
.....................................................................................................................................
41
9.7 安全事件应急
.........................
................................................................................................................
43
参 考 文 献
.......................................................................................................................................................
46
文档被以下合辑收录
评论