- 14
- 0
- 约1.76万字
- 约 37页
- 2023-08-04 发布于江苏
- 举报
信息系统安全管理规定
TOC \o 1-3 \h \z \u 1. 概述 4
2. 系统安全管理 4
1.1. 操作系统安全 4
1.2. 顾客安全 4
1.3. 服务器定期巡检 5
1.4. 安全监控 5
1.5. 系统安全测试 5
3. 设备安全管理 5
3.1. 防火墙安装与维护 5
3.2. 防火墙布署方略 6
3.3. 3.防火墙配置原则 6
3.4. 其他配置 7
3.4.1. 日志监控 7
3.4.2. 日志管理 8
3.4.3. 更新服务 8
4. 应用安全管理 8
4.1. 概述 8
4.2. 商业风险 8
4.3. 规范要素 9
4.3.1. XSS 9
4.3.2. 注入式袭击 9
4.3.3. Insecure Remote File Include 9
4.3.4. Insecure Direct Object Reference 9
4.3.5. CSRF 9
4.3.6. Information Leakage and Improper Error Handling 10
4.3.7. Broken Authentication and Session Management 10
4.3.8
原创力文档

文档评论(0)