企业信息安全架构设计分析
2019-10-21向德军胡鑫
向德军 胡鑫



摘要:随着互联网+战略的不断推进,越来越多的企业投入到信息化的浪潮之中。然而,信息化并不是简单的业务上线,还需要应对网络安全威胁等问题,因此安全技术的保驾护航必不可少。本文以某省电力交易中心信息化安全架构实践为案例,分析了电力企业面临的网络安全问题。同时,借鉴国际先进信息安全架构设计方案,为企业信息安全架构的搭建提供了合理的功能分类方法,并提出了夯实基础、修补短板、深化建设三步走的信息安全架构战略,为我国信息化企业的安全建设做出了实践性的探索。
关键词:安全架构;信息化;电力安全
Abstract:As the Internet+ strategy moves forward constantly, more and more enterprises are devoted to the wave of informatization. However, informatization is not a simple online business ,in order to deal with network security threats and other issues, it is more necessary to get support on security technology. This p vh ujh l,m g fg fgvv rtg aper analyzes the network security problems faced byelectronic power companies by taking the practice of information security architecture of a provincial electronic power exchange center as a case. Meanwhile, drawing experience from the international advanced informatization security architecture, a reasonable design plan has been provided for informatizing enterprises. Finally, a three-step informatization security architecture strategy, which is to put forward to consolidate the foundation, repair shortcomings and deepen the construction, has taken a practical exploration for China's informatization security.
Keywords:security architecture; informatization; electronic power security
0 引言
信息技术的发展不断加深社会生产对信息网络的依赖,使得信息化成为企业转型升级必不可少的一项重要举措。一方面,信息化有效提升企业的业务能力,使之更好地获取用户,增加收入;另一方面,信息化帮助企业减少成本、推进精益化管理,推动资源利用高效化,提高了企业的市场竞争力。
但同时,信息化企业也面临着潜在的信息安全问题。辛耀中(2001)通过对电网技术发展趋势的研究,总结出六大网络安全威胁:
这些网络威胁成为企业信息化的阻碍,因此,保障企业信息安全,构建信息安全体系架构成为信息化过程中的重要议题。
1 企业信息化安全架构现状分析
1.1 企业信息化安全现状
我国企业信息化安全仍处于初步发展阶段,电力企业整体安全架构系统还不成熟,安全防护能力较弱、对潜在的安全威胁识别能力较低。……
