摘要
This article proposes that problems of information security are mainly caused by the ineffective integration of people, operation, and technology, and not merely by the poor use of technology. Based on the information lifecycle, a model of the information security assurance lifecycle is presented. The crucial parts of the model are further discussed, with the information risk value and protect level, and the solution in each step of the lifecycle is presented with an ensured information risk level, in term of the integration of people, operation, and technology.
作者简介
XIE Cheng-shan, from Ministry of Information Industry, senior engineer, Post Doctor of State Key Laboratory of Information Security, interested in the research on information security.E-mail: xcswl@ 126.comXUJIA Gu-yue, School of Economic and Management, Beihang University, master, interested in the research on information system, knowledge management.WANG Li, School of Economic and Management, Beihang University, Ph. D. post doctor, interested in the research on DSS, knowledge management.