GB/T 28454-2012 in English
SUPERSEDEDInformation technology—Security techniques—Selection,deployment and operations of intrusion detection systems
- Issued on:2012-06-29
- Implemented on:2012-10-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$582.00
《GB/T 28454-2012信息技术 安全技术 入侵检测系统的选择、部署和操作》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Scope
This standard gives guidance to help organizations prepare to deploy IDS. In particular, the selection, deployment, and operation of IDSs are detailed. Background information on the sources of these guidelines is also given. The purpose of this standard is to help organizations: a) Meet the following requirements of GB/T 22080-2008: Organizations should implement procedures and other control measures that can improve the ability to detect and respond to security incidents; Organizations should implement monitoring and review procedures and other control measures , to identify potential or existing security vulnerabilities and incidents. b) In terms of implementing control measures, meet the following security objectives of GB/T 22081-2008: Detect unauthorized information processing activities; should monitor the system and record information security events; operation logs and fault logs should be used to ensure the identification of information system problems ; The organization should comply with all relevant legal requirements for monitoring and logging activities; The monitoring system should be used to check the effectiveness of the controls adopted and to verify compliance with the access control policy model. Organizations should recognize that IDS deployments are not the only or perfect solution to meeting the above requirements. Furthermore, this International Standard is intended to serve as a criterion for conformity assessment, such as information security management system (ISMS) certification, IDS service or product certification.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 25056-2018 in English
Information security technology—Specifications of cryptograph and related security technology for certificate authentication system
2018-06-07 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 31495.1-2015 in English
Information security technology―Indicator system of information security assurance and evaluation methods―Part 1:Concepts and model
2015-05-15 -

GB/T 40018-2021 in English
Information security technology—Certificate request and application protocol based on multiple channels
2021-04-30 -

GB/T 38249-2019 in English
Information security technology—Security guide of cloud computing services for government website
2019-10-18 -

GB/T 32213-2015 in English
Information security technology―Public key infrastructure―Specification for remote password authentication and key establishment
2015-12-10