GB/T 20261-2006 in English
SUPERSEDEDInformation technology--Systems security engineering--Capability maturity model
- Issued on:2006-03-14
- Implemented on:2006-07-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$1,455.00
《GB/T 20261-2006信息技术 系统安全工程 能力成熟度模型》由TC28(全国信息技术标准化技术委员会)归口,主管部门为国家标准化管理委员会。
本标准是系统安全工程的一个过程参考模型,关注的是信息技术安全领域内某个或若干个相关系统实现安全的需求,主要描述了用来实现信息技术安全的过程,尤其是过程的成熟度。
Scope
The System Security Engineering Capability Maturity Model (hereinafter referred to as SSE-CMM) is a process reference model. It focuses on the security requirements of a system or several related systems in the field of information technology security (ITS). Within the field of ITS, the SSE-CMM focuses on the processes used to achieve ITS, especially the maturity of these processes. The purpose of the SSE-CMM is not to prescribe specific processes, let alone specific methods, used by organizations. Rather, it is expected that organizations preparing to use the SSE-CMM will leverage their existing processes -- those that are based on any other IT security guidance document. The scope of this standard includes: System security engineering activities involving the entire life cycle of secure products or trusted systems: concept definition, requirements analysis, design, development, integration, installation, operation, maintenance and final decommissioning; System developers and integrators, and the requirements of organizations providing computer security services and computer security engineering; applicable to security engineering organizations of all types and sizes, from business to government and academia.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 36466-2018 in English
Information security technology—Implementation guide to risk assessment of industrial control systems
2018-06-07 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/Z 28828-2012 in English
Information security technology - Guideline for personal information protection within information system for public and commercial services
2012-11-05 -

GB/T 34095-2017 in English
中华人民共和国国家质量监督检验检疫总局 中国国家标准化管理委员会
2017-07-31 -

GB/T 36618-2018 in English
Information security technology—Specification for financial information service security
2018-09-17 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02