当前位置:首页 >英文主页 >中英对照 > 报告详情

美国国家标准与技术研究院:2025网络安全风险管理事件响应建议指南(英文版)(48页).pdf

上传人: Y**** 编号:630516 2025-04-23 48页 1,016.18KB

下载:

1、NIST Special Publication 800 NIST SP 800-61r3Incident Response Recommendations and Considerations for Cybersecurity Risk Management A CSF 2.0 Community Profile Alex Nelson Sanjay Rekhi Murugiah Souppaya Karen Scarfone This publication is available free of charge from:https:/doi.org/10.6028/NIST.SP.8

2、00-61r3 NIST Special Publication 800 NIST SP 800-61r3 Incident Response Recommendations and Considerations for Cybersecurity Risk Management A CSF 2.0 Community Profile Alex Nelson Sanjay Rekhi Murugiah Souppaya*Computer Security Division Information Technology Laboratory Karen Scarfone Scarfone Cyb

3、ersecurity*Former NIST employee;all work for this publication was done while at NIST.This publication is available free of charge from:https:/doi.org/10.6028/NIST.SP.800-61r3 April 2025 U.S.Department of Commerce Howard Lutnick,Secretary of Commerce National Institute of Standards and Technology Cra

4、ig Burkhardt,Acting Under Secretary of Commerce for Standards and Technology and Acting NIST Director NIST SP 800-61r3 Incident Response Recommendations and April 2025 Considerations for Cyber Risk Management Certain equipment,instruments,software,or materials,commercial or non-commercial,are identi

5、fied in this paper in order to specify the experimental procedure adequately.Such identification does not imply recommendation or endorsement of any product or service by NIST,nor does it imply that the materials or equipment identified are necessarily the best available for the purpose.There may be

6、 references in this publication to other publications currently under development by NIST in accordance with its assigned statutory responsibilities.The information in this publication,including concepts and methodologies,may be used by federal agencies even before the completion of such companion p

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要讨论了网络安全事件响应的重要性,以及如何将网络安全事件响应整合到网络安全风险管理中。文章提出了一个基于NIST网络安全框架(CSF 2.0)的事件响应生命周期模型,该模型包含六个功能:治理、识别、保护、检测、响应和恢复。文章还强调了组织内外许多个人、团队和第三方在所有功能中承担的广泛角色和责任。此外,文章还讨论了事件响应政策、流程和程序,并定义了NIST的CSF 2.0社区配置文件,以突出和优先考虑对事件响应重要的网络安全成果。
如何在组织中整合网络安全事件响应? 网络安全事件响应生命周期模型有哪些关键要素? 网络安全事件响应有哪些主要角色和责任?
客服
商务合作
小程序
服务号
折叠