当前位置:网站首页>What does grade evaluation mean? What is included in the workflow?
What does grade evaluation mean? What is included in the workflow?
2022-06-30 21:13:00 【Xingyun housekeeper】
Equal insurance 2.0 The policy is in full swing , However, there are still many enterprises for waiting insurance 2.0 The policy is not well understood , For example, I don't know what grade evaluation means ? What is included in the workflow, etc . Today we will give you a brief explanation .
What does grade evaluation mean ?
Grade evaluation refers to the evaluation of information security grade protection , Simply put, it is the evaluation of the protection of information and its carriers according to their importance . Specifically, it is a qualified evaluation institution certified by the Ministry of public security , According to the national code for classified protection of information security , Entrusted by relevant units , In accordance with the relevant management norms and technical standards , The activity of testing and evaluating the security level protection status of information system .
What does the rating evaluation workflow include ?
1、 System grading , For business 、 assets 、 Research on safety technology and safety management , Determine the grading system , Prepare the grading report , Provide assistance in grading service , Assist the user to complete the grading report , Organize expert review ;
2、 Equal warranty filing , Take the grading report and filing form to the local public security network supervisor for system filing ;
3、 Construction rectification , Refer to grading requirements and Standards , Rectify and reinforce the information system , Build a safety management system ;
4、 Rating , The evaluation organization evaluates the information system level , Form evaluation report ;
5、 Compliance supervision and inspection , Submit the evaluation report to the local public security network supervisor , The public security organ shall supervise and inspect the work of graded protection .
Knowledge development : Description of basic evaluation activities of grade evaluation
1、 Evaluation preparation activities
This activity is the premise and foundation of grade evaluation , It is the guarantee of the effectiveness of the whole grade evaluation process . Whether the evaluation preparation is sufficient is directly related to whether the follow-up work can be carried out smoothly . The main task of this activity is to master the details of the tested system , Prepare test tools , Prepare for the preparation of evaluation scheme .
2、 Programming activities
This activity is the key activity to carry out grade evaluation , Provide the most basic documents and guidance scheme for on-site evaluation . The main task of this activity is to determine the evaluation object suitable for the tested information system 、 Evaluation index and evaluation content, etc , And reuse or develop evaluation instructions as needed , Form evaluation scheme .
3、 On site evaluation activities
This activity is the core activity of grade evaluation . The main task of this activity is to meet the overall requirements of the evaluation scheme , Strictly implement the evaluation instructions , Implement all evaluation items step by step , Including unit evaluation and overall evaluation , To understand the real protection of the system , Get enough evidence , Find security problems in the system .
4、 Analysis and report preparation activities
This activity is to give the results of grade evaluation , It is a comprehensive evaluation activity to summarize the overall safety protection capability of the tested system . The main task of this activity is based on the on-site evaluation results and the relevant requirements of the insurance policy , It is determined by the results of individual evaluation 、 Unit evaluation result judgment 、 Methods such as overall evaluation and risk analysis , Find out the gap between the safety protection status of the whole system and the protection requirements of the corresponding level , And analyze the risks faced by the tested system due to these gaps , So as to give the grade evaluation conclusion , Form the evaluation report text .
边栏推荐
- Internet of things botnet gafgyt family and backdoor vulnerability exploitation of Internet of things devices
- Electronic scheme development - Intelligent rope skipping scheme
- B_QuRT_User_Guide(31)
- ca i啊几次哦啊句iu家哦11111
- 数字货币:影响深远的创新
- 1.微信小程序页面跳转方法总结;2. navigateTo堆栈到十层不跳转问题
- 等级测评是什么意思?工作流程包含哪些?
- Web APIs 综合案例-Tab栏切换 丨黑马程序员
- 为什么vscode用久了电脑速度变慢?
- 注册设备监理师难考吗,和监理工程师有什么关系?
猜你喜欢

《大厂面试》之JVM篇21问与答

Iclr'22 spotlight | how to measure the amount of information in neural network weights?

文本生成模型退化怎么办?SimCTG 告诉你答案

为什么vscode用久了电脑速度变慢?

开源实习经验分享:openEuler软件包加固测试

Oracle 数据库表结构 Excel 导出

【数字IC应届生职业规划】Chap.1 IC行业产业链概述及代表企业大厂汇总

Icml2022 | utility theory of sequential decision making

Adobe Photoshop (PS) - script development - remove file bloated script

Vite2兼容低版本chrome(如搜狗80),通过polyfills处理部分需求高版本的语法
随机推荐
时空数据挖掘:综述
B_QuRT_User_Guide(33)
Use the log server to output the topn of various Apache logs
Failed to configure a DataSource: ‘url‘ attribute is not specified and no embedded datasource could
FreeRTOS记录(九、一个裸机工程转FreeRTOS的实例)
针对美国国家安全局“酸狐狸”漏洞攻击武器平台的分析与应对方案建议
How to move forward when facing confusion in scientific research? How to give full play to women's advantages in scientific research?
mysql-批量更新
uniapp-富文本编辑器
Auto-created primary key used when not defining a primary key
3Ds Max 精模obj模型导入ArcGIS Pro (二)要点补充
两个skyline
Peking University ACM problems 1003:hangover
修改已经上线的小程序名称
文本生成模型退化怎么办?SimCTG 告诉你答案
B_QuRT_User_Guide(31)
qiao-npms:搜索npm包
ICLR'22 Spotlight | 怎样度量神经网络权重中的信息量?
asp.net core JWT传递
Metauniverse may become a new direction of Internet development