中国网络安全等级保护制度理解与实施(英文版)
上QQ阅读APP看书,第一时间看更新

Foreword

注释

[1]For example, United States’ National Institute of Standards and Technology (NIST)’s Federal Information Processing Standards Publication (FIPS PUB) 199 (2004), Standards for Security Categorization of Federal Information and Information Systems uses impact assessment for categorizing the criticality of information systems into LOW, MEDIUM, and HIGH categories, which is then used for selecting security and privacy controls (based on NIST Special Publication 800-53) required for protection of federal information systems and organizations at that level. While terminologies and implementation defer, the principal approach adopted by China’s Cybersecurity Classified Protection System is similar.