|
Security standards广告 Security standardsSecurity standards and security organizationsThe National Computer Security Center (NCSC) is one organization that promotes security standards amongst governmental and other organizations. It has formulated a number of security standards, the most well known being the Trusted Computer System Evaluation Criteria (TCSEC), which contains seven levels of criteria for a trusted system.
Several other computer-security-related organizations provide information on security threats and possible workarounds. The most prominent are
Intrusion-detection softwareIntrusion-detection software has been around for a while, but has recently become more popular. It can be set up to monitor network traffic and shut down connections deemed unsafe. The software works by comparing the flow of network traffic to a set of rules and then responding if violations of the rules occur. Intrusion-detection programs rely on a predefined database of attack signatures. When activity is observed that conforms to one of the attack signatures, the program responds. As an administrator, you decide what actions the software takes, ranging from informing you, through firewall reprogramming to punishing hacker activity. Although such software is useful and effective, you shouldn't let its use replace regular security checks and audits. The programs are not perfect and sometimes have difficulty in differentiating normal, safe network activity from actual attack—this is called a false positive. For this reason, and the fact that intrusion-detection programs are quite difficult to set up and maintain, not all administrators have adopted them. Popular intrusion-detection programs include: Other useful linksThe Internet Computer Security
Association ISS
RealSecure
Internet Detection
Software Microsoft's
Security Page 如果您希望与本文章的作者或其所在机构,进一步交流,请联系:畅享网 姜小姐 jill.jiang@amteam.org | 021-51096826-112 | 在线联系 |
前沿论丛2009年第三期——知识管理..国内中小企业普遍存在管理基础薄弱、规范化程度低、信息化基础差等方面的问题,而知识管理的实施难度甚至要高于ERP的实施,因为简单的从上而下压迫式的推行只能做到知识…… |
|
|