基于SPM方法的S石化公司信息安全管理策略的研究
發(fā)布時(shí)間:2018-06-24 02:58
本文選題:信息安全 + SPM; 參考:《上海交通大學(xué)》2015年碩士論文
【摘要】:云計(jì)算、大數(shù)據(jù)和新型社交網(wǎng)絡(luò)等信息爆炸發(fā)展的時(shí)代,在為人們生活帶來(lái)便利的同時(shí),一方面為企業(yè)的發(fā)展帶來(lái)了機(jī)遇,信息數(shù)據(jù)的海量存儲(chǔ)、管理和分析可以協(xié)助企業(yè)更好地經(jīng)營(yíng)發(fā)展;另一方面也為企業(yè)帶來(lái)了新的挑戰(zhàn),如何更加安全有效地使用和管理這些信息數(shù)據(jù)是企業(yè)需要思考的問題。本文將以S石化公司為例,根據(jù)公司發(fā)展發(fā)現(xiàn)公司在信息安全管理方面現(xiàn)存在的問題,并借助于安全全球的信息安全評(píng)估和規(guī)劃SMP方法對(duì)公司進(jìn)行全面分析和診斷,最后分別從組織人員、信息安全管理和信息安全技術(shù)層面對(duì)S石化公司作出速盈整改建議策略,希望對(duì)公司的整體長(zhǎng)期發(fā)展具有一定的指導(dǎo)意義。首先本文將對(duì)S石化公司的現(xiàn)狀進(jìn)行介紹,同時(shí)主要從風(fēng)險(xiǎn)值、成熟度評(píng)分和差異分析等維度對(duì)S石化公司的信息安全現(xiàn)狀進(jìn)行介紹。然后文章在SPM分析法框架的支撐和約束下,對(duì)公司的信息安全管控進(jìn)行詳細(xì)的信息安全現(xiàn)狀分析找出公司存在的不足,其中主要從組織人員、管理安全和技術(shù)安全等方面進(jìn)行詳細(xì)分析說(shuō)明;趯(duì)公司發(fā)展的充分理解,隨后本論文在結(jié)合實(shí)施緊迫度,風(fēng)險(xiǎn)評(píng)估效果,實(shí)施效益以及技術(shù)可行性等角度,針對(duì)上文對(duì)S石化公司提出的問題依次提出速盈整改建議策略,目的在于幫助S石化公司解決信息安全威脅,同時(shí)更好的幫助公司建設(shè)主動(dòng)式信息安全預(yù)防體系,保證信息安全工作支持IT規(guī)劃目標(biāo)的。最后論文總結(jié)概述S石化公司信息安全管理策略,并將結(jié)合現(xiàn)實(shí)操作等不可預(yù)測(cè)因素對(duì)提出的策略指出本文仍存在的不足以及下一步要做的工作。
[Abstract]:With the development of cloud computing, big data, new social network and other information explosion, it not only brings convenience to people's life, but also brings opportunities for the development of enterprises, massive storage of information data. Management and analysis can help enterprises to manage and develop better, on the other hand, it also brings new challenges to enterprises. How to use and manage these information data more safely and effectively is the problem that enterprises need to think about. In this paper, taking S Petrochemical Company as an example, according to the development of the company, we will discover the existing problems in the information security management of the company, and make a comprehensive analysis and diagnosis of the company by means of the information security assessment and planning SMP method of the global security. In the end, the author makes suggestions to S Petrochemical Company from the aspects of organization personnel, information security management and information security technology, hoping to have certain guiding significance for the overall long-term development of the company. First, this paper will introduce the present situation of S petrochemical company, and introduce the present situation of information security of S petrochemical company from the aspects of risk value, maturity score and difference analysis. Then, under the support and constraint of SPM analysis framework, the paper analyzes the current situation of information security of the company in detail, and finds out the shortcomings of the company, mainly from the organization personnel. Management safety and technical safety and other aspects of detailed analysis. Based on the full understanding of the development of the company, then this paper combines the implementation urgency, risk evaluation effect, implementation benefit and technical feasibility, and puts forward the proposed strategy of quick profit rectification for the problems raised by S Petrochemical Company. The purpose is to help S Petrochemical Company to solve the threat of information security, at the same time to help the company to build a proactive information security prevention system, to ensure that information security work supports IT planning objectives. Finally, the paper summarizes and summarizes the information security management strategy of S Petrochemical Company, and points out the shortcomings of this paper and the work to be done in the next step, combining with the unpredictable factors such as practical operation.
【學(xué)位授予單位】:上海交通大學(xué)
【學(xué)位級(jí)別】:碩士
【學(xué)位授予年份】:2015
【分類號(hào)】:F270.7;F426.72;TP309
,
本文編號(hào):2059693
本文鏈接:http://sikaile.net/guanlilunwen/shengchanguanlilunwen/2059693.html
最近更新
教材專著