摘要
近年来,随着高校智慧校园的建设和发展,高校的信息资产也随之快速增加。这些承载着丰富功能与重要数据的信息系统不仅成为黑客攻击的目标,致使网络安全问题频发;同时,数量众多、产权不明的信息系统也给管理带来极大困难。文章以长沙理工大学为例,首先阐述了当前信息资产管理的现状及所面临的各种问题;其次提出使用信息安全治理平台管理高校信息资产,该平台整合了资产梳理、资产备案、自动化运营、应急响应、漏洞整改等多项功能;最后提出了一种立体化防御方案,初步实现了让信息资产责权清晰、安全管理到位的治理目标。
In recent years,with the construction and development of smart campuses in colleges and universities,the information assets of universities have also increased rapidly.These information systems,which carry rich functions and important data,have not only become targets for hacker attacks,leading to frequent cybersecurity issues,but the large number of information systems with unclear property rights have also brought great difficulties to managers.Taking Changsha University of Science and Technology as an example,this paper firstly elaborates on the current status of information asset management and the various problems faced,and proposes the use of an information security governance platform to manage university information assets.This platform integrates functions such as asset sorting,asset filing,automated operation,emergency response,and vulnerability rectification.Finally,a three-dimensional defense scheme is proposed,initially achieving the governance goals of clear responsibility and authority for information assets and effective security management.
作者
邝剑飞
王威
KUANG Jianfei;WANG Wei(Information Technology Construction Management Department,Changsha University of Science and Technology,Changsha 410114,China;School of Computer and Communication Engineering,Changsha University of Science and Technology,Changsha 410114,China)
出处
《现代信息科技》
2024年第17期144-149,154,共7页
Modern Information Technology
关键词
信息资产
网络安全
平台化
information assets
network security
platformisation