当前位置:网站首页>If the evaluation conclusion of waiting insurance is poor, does it mean that waiting insurance has been done in vain?
If the evaluation conclusion of waiting insurance is poor, does it mean that waiting insurance has been done in vain?
2022-06-29 18:03:00 【Xingyun housekeeper】
When surfing the Internet recently , Ask again when you see an enterprise , The evaluation conclusion of ISO insurance is poor , Does it mean that the insurance work has been done in vain ? How to deal with this situation ? Who can answer it in detail , Thank you guys !
The evaluation conclusion of ISO insurance is poor , Does it mean that the insurance work has been done in vain ?
【 answer 】: No, it isn't . The conclusion of the grading protection evaluation is “ Bad ”, It means that the current information system has high risk or poor overall security , It doesn't meet the requirements of corresponding standards . But it doesn't mean that the work of classified protection has been done in vain , Even if you have a non compliant evaluation report , The competent authorities also acknowledge that the work of classified protection in your unit has been carried out this year , It's just that there are many problems at present , Not up to the standard , We need to speed up the rectification . So we must seize the time to rectify .
Summary of high-risk items that lead to poor evaluation conclusion of equal assurance in equal assurance work
1、 Cloud computing platform is not available in China
The cloud computing infrastructure of level II and above cloud computing platforms shall be located in China . If you choose an overseas cloud platform , Then you can't pass the insurance .
2、 Only one internal network segment does not conform to
Secondary and above systems , Important network areas and non important network areas shall be divided into different network segments or subnets . Production network and office network , External and internal server areas are mixed with high-risk risks .
3、 The uncontrolled wireless network can access the internal network at will
Class III and above systems of equal protection , Wireless network and important internal network interconnection are not controlled , Or improper control , After accessing through wireless network, you can access important internal resources , This is a high risk item , Therefore, illegal access should be controlled in Level 3 and above systems , It is recommended that you use safety access equipment , Not just for wireless networks .
Classification standard for conclusion level of ISO guarantee evaluation
1、 optimal : There are security problems in the tested object , But it will not cause the tested object to face 、 High level security risk , And the comprehensive score of the system 90 More than , contain 90 branch ;
2、 good : There are security problems in the tested object , However, it will not cause the tested object to face high-level security risks , And the comprehensive score of the system 80 More than , contain 80 branch ;
3、 in : There are security problems in the tested object , However, it will not cause the tested object to face high-level security risks , And the comprehensive score of the system 70 More than , contain 70 branch ;
4、 Bad : There are security problems in the tested object , And it will cause the measured object to face high-level security risks , Or the comprehensive score of the tested object is lower than 70 branch .
边栏推荐
- Servlet学生管理系统(萌新练手版)
- Yurun multidimensional makes efforts in the charity field and bravely resists the corporate public welfare banner
- 牛客小白月赛52 E 分组求对数和(容斥定理+二分)
- Timer interrupt experiment based on stm32f103zet6 library function
- selenium上传文件
- Kubekey2.2.1 kubernetes1.23.7 offline package production +harbor Department summer and upload image
- Let's start with a bug that was cheated by the app store
- Web Scraping with Beautiful Soup for Data Scientist
- js两个二维数组合并并去除相同项(整理)
- Visual studio plug-in coderush officially released v22.1 -- visual tool for optimizing debugging
猜你喜欢

第42期:MySQL 是否有必要多列分区

Let Google search your blog

js两个二维数组合并并去除相同项(整理)

Matlab farthest point sampling (FPS)

kubekey2.2.1 kubernetes1.23.7离线包制作+harbor部暑并上传镜像

分布式 | 几步快速拥有读写分离
![分割回文串[dp + dfs组合]](/img/7b/221b000984977508f849e19802c2c2.png)
分割回文串[dp + dfs组合]

Niuke small Bai monthly race 52 D ring insectivorous (feet +st table)

Precondition end of script headers or end of script output before headers
MySql存储过程循环的使用分析详解
随机推荐
/usr/bin/ld: warning: **libmysqlclient.so.20**, needed by //usr/
软件快速交付真的需要以安全为代价吗?
codeforces每日5题(均1700)-第二天
Sword finger offer 13 Robot range of motion (BFS)
Mysql database literacy, do you really know what a database is
2022 spring summer collection koreano essential reshapes the vitality of fashion
POJ 1975 (transitive closure)
回文子串的最大长度(字符串哈希+二分)
SSH协议学习笔记
【TcaplusDB知识库】TcaplusDB系统用户组介绍
3h精通OpenCV(五)-透视变换
Fill in the next right node pointer of each node [make good use of each point - > reduce the space-time complexity as much as possible]
Timer interrupt experiment based on stm32f103zet6 library function
国内酒店交易DDD应用与实践——理论篇
面试中问最常问的海量数据处理你拿捏了没?
selenium 组合键操作
工作流模块Jar包启动报错:liquibase – Waiting for changelog lock….
What value can SRM systems bring to the enterprise?
Goldfish rhca memoirs: do447 build advanced job workflow -- create job template survey to set work variables
最长异或路径(dfs+01trie)