Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Введение в информационную безопасность и защиту информации. Учебное пособие

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
Правовая защита информации:
Защита информации правовыми ме­тодами, включающая в себя разработ­ку законодательных и нормативных правовых документов (актов), регу­лирующих отношения субъектов по защите информации, применение этих документов (актов), а также надзор и контроль за их исполнением. [ГОСТ Р 50922-2006, 2.2.1]
Разглашение информации: Несанк­ционированное доведение защищае­мой информации до лиц, не имеющих права доступа к этой информации.
[ГОСТ Р 53114-2008 3.3.11]
Распространение персональных данных – действия, направленные на
передачу персональных данных опре­деленному кругу лиц (передача персо­нальных данных) или на ознакомление с персональными данными неограни­ченного круга лиц, в том числе обна­родование персональных данных в средствах массовой информации, раз­мещение в информационно-телеко­ммуникационных сетях или предо­ставление доступа к
персональным данным каким-либо иным способом. [Методические рекомендации по обеспечению с помощью крипто­средств безопасности персональных данных при их обработке в информа­ционных системах персональных данных с использованием средств автоматизации]
Регистрация – регистрация – проце­дура, посредством которой какой­либо орган фиксирует соответствую­щие признаки продукции, процесса
Legal protection of information: data protection of legal methods, including the development of legislative and regu­latory documents (acts) that regulate subjects regarding the protection of in­formation, using of these documents (acts), as well as supervision and control over their execution.
Inadvertent Disclosure – Type of inci­dent involving accidental exposure of information to an
individual not authorized access. SOURCE: CNSSI-4009
Distribution of personal data – actions aimed to the transfer of personal data defined group of individuals (personal data) or to become acquainted with the personal data the general public, includ­ing disclosure of personal information in the media, placement in the information and telecommunications networks or the provision of access to personal data in any other way.
Registration – The process through which a party applies to become a sub­scriber of a Credentials Service Provider (CSP) and a Registration Authority
81
или услуги либо особенности органа или лица в соответствующем общедо­ступном перечне;
[ГОСТ Р 1.12-99: Государствен­ная система стандартизации Россий­ской Федерации. Стандартиза­ция и смежные виды деятельности. Термины и определения] регистрация – завершение идентификации и аутентификации пользователя; [ГОСТ Р ИСО/ТО 13569-2007: Фи­нансовые услуги. Рекомендации по информационной безопасности] реги­страция
– начальный этап процесса осуществления взаимодействия ра­диочастотной метки с устройством считывания/опроса;
[ГОСТ Р ИСО/МЭК 19762-3-2011: Информационные технологии. Тех­нологии автоматической идентифи­кации и сбора данных (АИСД). Гар­монизированный словарь. Часть 3. Радиочастотная идентификация (РЧИ)] регистрация – процесс полу­чения биометрического образца от конечного пользователя;
[ГОСТ Р ИСО/МЭК 19794-10­2010: Автоматическая идентифика-
ция. Идентификациябиометрическая. Форматы обмена биометрическими данными. Часть 10. Данные геомет­рии контура кисти руки] регистра­ция – процесс предоставления личной идентификационной информации биометрической системе, сопоставле­ния уникального идентификатора с данной идентификационной инфор­мацией, сбор и запись соответствую­щей личной информации в систему.
validates the identity of that party on behalf of the CSP. SOURCE: CNSSI­4009 The process through which an Ap­plicant applies to become a Subscriber of a CSP and an RA validates the identi­ty of the Applicant on behalf of the CSP. SOURCE: SP 800-63
82
[ГОСТ Р ИСО/МЭК 24713-2-2011:
Информационные технологии. Био­метрия. Биометрические профили для взаимодействия и обмена данны­ми. Часть 2. Контроль физическо­го доступа сотрудников аэропортов]
Режим секретности – совокупность определяемых органами власти и управления правил, которыми огра­ничивается допуск лиц к секретным материалам и работам, регламентиру­ется порядок пользования секретных материалов, соответствующим обра­зом регулируется поведение людей, имеющих отношение к секретам, и предусматриваются другие меры.
Риск: Влияние неопределенностей на процесс достижения поставленных целей.
[ГОСТ Р 53114-2008 3.2.9]
Security Marking – Human-readable
information affixed to information sys­tem components, removable media, or output indicating the distribution limita­tions, handling caveats, and applicable security markings. SOURCE: SP 800-53
Risk – The level of impact on organiza­tional operations (including mission, functions, image, or reputation), organi­zational assets, or individuals resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring.
SOURCE: FIPS 200 The level of impact on organizational
operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation resulting from the opera­tion of an information system given the potential impact of a threat and the like­lihood of that threat occurring.
SOURCE: SP 800-60 A measure of the extent to which an enti­ty is threatened by a potential circum-
stance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs;
83
and (ii) the likelihood of occurrence.
Note: Information system-related securi­ty risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or infor­mation systems and consider the adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, indi­viduals, other organizations, and the Nation.
SOURCE: SP 800-53 A measure of the extent to which an
entity is threatened by a potential cir­cumstance or event, and typically a function of: (1) the adverse impacts that would arise if the circumstance or event occurs;
and (2) the likelihood of occurrence. Note: Information system-related securi-
ty risks are those risks that arise from the loss of confidentiality, integri-
ty, or availability of information or information systems and reflect the po-
tential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation. SOURCE: CNSSI-4009
A measure of the extent to which an entity is threatened by a potential cir­cumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occur­rence.
84
Сертификация на соответствие требованиям по безопасности ин­формации – форма осуществляемого
органом по сертификации подтвер­ждения соответствия объектов оценки требованиям по безопасности инфор­мации, установленным техническими регламентами, стандартами или усло­виями договоров.
ГОСТ Р 50922 2006
[Note: Information system-related secu­rity risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or infor­mation systems and reflect the potential adverse impacts to organizational opera­tions (including mission, functions, im­age, or reputation), organizational assets,
individuals, other organizations, and the Nation. Adverse impacts to the Nation include, for example, compromises to information systems that support critical
infrastructure applications or are para­mount to government continuity of op­erations as defined by the Department of Homeland Security.] SOURCE: SP 800-37; SP 800-53A
Certification
A comprehensive assessment of the management, operational, and technical security controls in an information sys­tem, made in support of security accredi­tation, to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
SOURCE: FIPS 200 The process of verifying the correctness of a statement or claim and issuing a
certificate as to its correctness. SOURCE: FIPS 201 Comprehensive evaluation of the tech-
nical and nontechnical security safe­guards of an information system to sup­port the accreditation process that estab­lishes the extent to which a particular design and implementation meets a set of specified security requirements.
SOURCE: CNSSI-4009
85
Сигнализация попыток нарушения защиты.
Система:
защиты информации (СЗИ) - ком­плекс организационных мер и про­граммно-технических (в том числе криптографических) средств обеспе­чения безопасности информации в автоматизированных системах;
[Руководящий документ Защита от несанкционированного доступа к ин­формации Термины и определения, пункт 34.]
– защиты информации от несанк­ционированного доступа (СЗИ НСД) – комплекс организационных
и программно-технических (в том
мер числе криптографических) средств защиты от несанкционированного доступа к информации в автоматизи­рованных системах.
[Руководящий документ Защита от несанкционированного доступа к ин­формации Термины и определения, пункт 35.]
Система защиты информации: Со- вокупность органов и (или) исполни­телей, используемой ими техники защиты информации, а также объек­тов защиты информации, организо­ванная и функционирующая по пра­вилам и нормам, установленным со­ответствующими документами в об­ласти защиты информации.
[ГОСТ Р 50922-2006, 2.4.3]
Alarm of attacks.
Information Systems Security Product
– Item (chip, module, assembly, or equipment), technique, or service that performs or relates to information sys­tems security. SOURCE: CNSSI-4009
Information Systems Security – (IN­FOSEC) Protection of information sys­tems against unauthorized access to or modification of information, whether in storage, processing, or transit, and against the denial of service to author­ized users, including those measures necessary to detect, document, and counter such threats. SOURCE: CNSSI-4009
Information Systems Security Product – Item (chip, module, assembly, or equipment), technique, or service that performs or relates to information sys­tems security. SOURCE: CNSSI-4009)
86
Система защиты информации от НСД (СЗИ НСД) – комплекс органи-
зационных мер и программно­технических (при необходимости криптографических) средств защиты от несанкционированного доступа к информации (несанкционированных действий с ней) в автоматизирован­ной системе.
СТРК-2001
Служба безопасности информации (служба защиты информации (в
АС)) – это самостоятельное подраз­деление предприятия, которое зани­мается решением проблем информа­ционной безопасности данной орга­низации.
System of protection of information from unauthorized access - a set of
organizational measures and the soft­ware and hardware (if necessary crypto­graphic) means of protection against unauthorized access to information (un­authorized actions with it) in an auto­mated system.
Information Systems Security Manag­er (ISSM) – Individual responsible for
the information assurance of a program, organization, system, or enclave. SOURCE: CNSSI-4009
Information Systems Security Officer (ISSO) – Individual assigned responsi-
bility for maintaining the appropriate operational security posture for an in­formation system or program. SOURCE: CNSSI-4009
Senior Agency Information Security Officer (SAISO) – Official responsible
for carrying out the Chief Information Officer responsibilities under the Federal Information Security Management
Act (FISMA) and serving as the Chief Information Officer’s primary liaison to the agency’s authorizing officials, in­formation system owners, and infor­mation system security officers. SP 800-53 Note: Organizations subordi­nate to federal agencies may use the term Senior Information Security Officer or Chief Information Security Officer to denote individuals filling positions with similar responsibilities to Senior Agency Information Security Officers.
87
Событие – факт, состоящий в том, что нечто произошло или в проблем­ной области, или в среде, или в ин­формационной системе.
[ГОСТ 34.320 96].
Специалист по защите информации.
Специальная защита – комплекс
организационных и технических ме­роприятий, обеспечивающих защиту информации от утечки по каналам побочных излучений и наводок. [Методические рекомендации по обеспечению с помощью крипто­средств безопасности персональных данных при их обработке в информа­ционных системах персональных данных с использованием средств автоматизации]
Специальная проверка - проверка объекта информатизации в целях вы­явления и изъятия возможно внед­ренных закладочных устройств.
ГОСТ Р 50922 2006
Специальное исследование (объек­та защиты информации) – Исследо-
вание, проводимое в целях выявления технических каналов утечки защища­емой информации и оценки
SOURCE: SP 800-53; SP 800-53A; SP 800-37; SP 800-60; FIPS
200; CNSSI-4009; 44 U.S.C., Sec. 3544 Information Security Service = SSI-
SO+ISSM+ISSO
Event – Any observable occurrence in a network or system. SOURCE: SP 800­61 Any observable occurrence in a sys­tem and/or network. Events sometimes provide indication that an incident is occurring. SOURCE: CNSSI-4009
Information Systems Security Manag­er (ISSM) – Individual responsible for
the information assurance of a program, organization, system, or enclave. SOURCE: CNSSI-4009
Special protection – a complex of or­ganizational and technical measures that protect information from leaking through the channels and spurious inter­ference.
Security Inspection – Examination of an information system to determine compliance with security policy, proce­dures, and practices.
SOURCE: CNSSI-4009
Security Test & Evaluation (ST&E) –
Examination and analysis of the safe­guards required to protect an infor­mation system, as they have been ap­plied in an operational environment,
88
соответствия защиты информации (на объекте защиты) требованиям нормативных и правовых документов
to determine the security posture of that system.
SOURCE: CNSSI-4009
в области безопасности информации. ГОСТ Р 50922 2006
Специальный персонал. Special staff. Способ защиты информации: Поря-
док и правила применения опреде­ленных принципов и средств защиты
Protective Measures Those actions, procedures, or designs implemented to safeguard protected information
информации. [ГОСТ Р 50922-2006, 2.3.1]
Средства:
– защиты – техническое, программ­ное, программно-техническое сред­ство, вещество и (или) материал, предназначенные или используемые для защиты информации;
[ГОСТ 50922-2006, пункт 2.7.2] – технические средства разведки; – технические средства промышлен-
ного шпионажа; – криптографической защиты - сред-
ство вычислительной техники, осу­ществляющее криптографическое преобразование информации для обеспечения ее безопасности;
[ГОСТ 50922-2006, пункт 2.7.5]: – аттестованные (
лицензированные); – сертифицированные; – вычислительной техники (СВТ); – восстановления (СЗИ НСД); – технические средства охраны; – оперативного контроля и воздей­ствия на безопасность АС. – периодического контроля за це- лостностью программной и информа-
Means:
– of protection – is technical, software, software and hardware, material and (or) material designed or implemented to protect information; – technical means of intelligence;
– technical means of industrial espio­nage;
– cryptographic protection - the means of ADP equipment which is realizing cryptography information transform for support of its safety;
– certified (licensed); – certified; – of computing; – of recovery (SPI UA); – technical means of protection; – of operational control and impact on the safety of the AS; – of periodic control over the integrity of the software and information complex protection; – of obtain registration information and the possibility of unauthorized users
from reading it.
ционной части КСЗ.
89
получения регистрационной ин-
формации и возможности санкциони­рованного ознакомления с ней.
Средство защиты информации –
техническое, программное, програм­мно-техническое средство, вещество и (или) материал, предназначенные или используемые для защиты ин­формации.
ГОСТ Р 50922 2006
Средство контроля эффективности защиты информации – средство
защиты информации, предназначен­ное или используемое для контроля эффективности защиты информации.
ГОСТ Р 50922 2006
Статус объектов доступа – текущее состояние объектов, к которым предоставляется доступ.
Строгий пропускной режим.
Субъект доступа – это лицо или про-
цесс, действия которого регламенти­руются правилами разграничения доступа.
[Руководящий документ Защита от несанкционированного доступа к ин­формации Термины и определения, пункт 6.]
Protective Measures – Those actions, procedures, or designs implemented to safeguard protected information.
Information Security Continuous Monitoring (ISCM) – Maintaining on-
going awareness of information security, vulnerabilities, and threats to support organizational risk management deci­sions.
The status of objects of access – a cur­rent status of objects to which access is provided.
Access Control – The process of grant­ing or denying specific requests to:
1) obtain and use information and relat­ed information processing services; and
2) enter specific physical facilities (e.g., federal buildings, military establish­ments, border crossing entrances).
SOURCE: FIPS 201; CNSSI-4009
Access Profile – Association of a user with a list of protected objects the user may access. SOURCE: CNSSI-4009
90
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]