论文部分内容阅读
针对学校内部的信息网络系统(IT)管理来说,主要包括网络管理和安全管理二个大的方面。IT应用发展到今天,网络管理已从设备的管理发展到网络应用的管理,信息安全已从网络的安全发展到应用安全的管理。那么如何能使IT管理者知道目前网络中的应用情况以及在应用上的安全问题呢?这就需要我们所说的安全审计,安全审计通过对IT系统中各个审计元素(网络设备、主机设备和应用系统运行以及网络通信活动)进行全面的监测记录并进行静态和动态的分析评估,使IT了解整个情况并可以发现应用和安全问题。所以,构建完整的信息安全审计系统是构建网络安全体系中的一个重要和关键部分。
For information network system (IT) management within the school, it mainly includes two aspects of network management and security management. Today, IT application development, network management has been developed from the management of equipment to the management of network applications, information security has been developed from the network security to application security management. So how to enable IT managers to know the current network applications and security issues in the application? This requires what we call the security audit, security audit through the IT system audit elements (network equipment, host equipment and Application system operations, and network communications activities) to conduct a comprehensive monitoring record and static and dynamic analysis and assessment to enable IT to understand the entire situation and can identify application and security issues. Therefore, building a complete information security audit system is an important and key part of building a network security system.