You are here

NISSG: "Network and Information Security Standards Report", versione definitiva (giugno 2007)

Il Network and Information Security Steering Group (NISSG), emanazione dell’ICT Standards Board, ha pubblicato in collaborazione con ENISA (European Network and Information Security Agency) la versione definitiva del "Network and Information Security Standards Report" (pdf, 529 K, 76 pp). Il rapporto contiene una sintesi dei principali standard in ambito NIS (Network and Information Security) insieme a raccomandazioni e suggerimenti per le azioni da intraprendere per contrastare le correlate minacce. Il documento insiste sull’importanza per il NIS non solo delle misure tecnologiche ma anche degli aspetti relativi alla gestione del personale (occorre una cultura della sicurezza) e alla condivisione delle “Best Practice” che devono basarsi su una preliminare comprensione dei rischi di sicurezza ed essere "ritagliate" sulle effettive necessità aziendali. Il rapporto contiene anche indicazioni specifiche per le piccole e medie imprese.

Aree analizzate

Le aree prese in considerazione per gli standard di sicurezza sono

  • registration, authentication and authorization services;
  • confidentiality and privacy services;
  • trust services;
  • network and information security management systems and services; 
  • assurance services.

Indice del documento

  • Version History
  • Executive Summary
  • 1 Introduction
  • 2 Threats referred to in COM(2006) 251
  • 3 Scope and Content of this Report
    • 3.1 Definitions
    • 3.2 Scope of this report
    • 3.3 Context of this report
  • 4 User Requirements
    • 4.1 Home Users
      • 4.1.1 Home Working
      • 4.1.2 Personal Business
      • 4.1.3 Microprocessor control of Domestic equipment
      • 4.1.4 eHealth
      • 4.1.5 General Security Requirements
    • 4.2 Small and Medium Enterprises
      • 4.2.1 The SME as a user of e-business services
      • 4.2.2 The SME as a supplier of e-business services
      • 4.2.3 General Security Requirements
    • 4.3 Large Organizations and industries
      • 4.3.1 General Security Requirements
  • 5 General Threats to Network and Information Security
  • 6 Registration, Authentication and Authorization Services
    • 6.1 Registration, Authentication and Authorization Processes
      • 6.1.1 Effective User Registration
      • 6.1.2 Effective User Identification
      • 6.1.3 Effective User Authentication
      • 6.1.4 Effective User Authorization/Access Control
      • 6.1.5 Effective User Management
      • 6.1.6 User Management in Healthcare
    • 6.2 Security Measures
      • 6.2.1 Passwords
      • 6.2.2 Biometrics
      • 6.2.3 Digital Certificates
      • 6.2.4 Smart Cards
  • 7 Confidentiality and Privacy Services
    • 7.1 Security Measures
    • 7.2 Encryption of stored information
    • 7.3 Electronic mail encryption
    • 7.4 Network Encryption
    • 7.5 Cryptographic Algorithms
    • 7.6 Privacy
    • 7.7 Media Disposal and Re-use Policy
  • 8 Trust Services
    • 8.1 Trust Service Processes
      • 8.1.1 General Key Management
      • 8.1.2 Public Key Management
      • 8.1.3 Non-Repudiation
      • 8.1.4 Trusted Commitment Service
      • 8.1.5 Content Integrity
    • 8.2 Security Measures
      • 8.2.1 Electronic signatures
      • 8.2.2 Hash Functions
      • 8.2.3 Time-stamping
    • 8.3 Harmonization of Trust Services
  • 9 Network and Information Security Management Services
    • 9.1 Security Measures
    • 9.2 Risk assessment
    • 9.3 Information security management standards
      • 9.3.1 27000 Family of standards
      • 9.3.2 Other standards for security measures and services
    • 9.4 Examples of security measures for business services
      • 9.4.1 Service Availability
      • 9.4.2 Information Availability
      • 9.4.3 Effective Accounting and Audit
      • 9.4.4 Failure Impact Analysis
      • 9.4.5 Capacity Planning
      • 9.4.6 Business Continuity Planning
      • 9.4.7 Configuration Management
      • 9.4.8 Checksums and Cyclic Redundancy Checks
    • 9.5 Examples of security measures for network defence services
      • 9.5.1 Preventive Measures
      • 9.5.2 Detection Measures
  • 10 Assurance Services
    • 10.1 Security Measures
    • 10.2 Product evaluation
    • 10.3 Information Security Management System Certification
    • 10.4 Accreditation Bodies
  • 11 Important NIS-related Topics outside the Scope of this Report
    • 11.1 Criminogenic ICT services and products
    • 11.2 eHealth
    • 11.3 Critical Infrastructures
      • 11.3.1 Pervasive ICT
      • 11.3.2 Consequences of pervasive use of ICT
      • 11.3.3 SCADA Standardization in Europe
    • 11.4 Autonomous ICT
    • 11.5 Issues not covered in this report
      • 11.5.1 Legal issues
      • 11.5.2 Personnel screening
      • 11.5.3 Information security professional qualifications
      • 11.5.4 Longevityof archiving
  • 12 New Developments
    • 12.1 RFID
      • 12.1.1 Security Threats
      • 12.1.2 Security solutions for deploying RFID Tags
    • 12.2 Next generation networks
  • 13 References
  • Annex 1 - Network Encryption
    • IPsec
    • TLS
    • Security in the Web Service World
  • Annex 2
    • Annex 2A - Overview of Information for Small and Medium Enterprises regarding Network and Information Security
    • Annex 2B - Überblick über Informationen über Netz- und Informationssicherheit für kleine und mittlere Unternehmen
    • Annex 2C –Informations relatives à la sécurité des réseaux et de l’information pour les Petites et Moyennes Entreprises (PME)
    • Annex 2D – Informaciones para las pequeñas y medianas empresas (PYME) sobre la seguridad de las redes y de la información
    • Annex 2E - Informazioni disponibili per le PMI (piccole e medie imprese) sulla sicurezza informatica e di rete
  • Annex 3 – Security-Related Projects within the EU
  • List of Abbreviations
  • List of Web Sites

Articoli collegati

Link

AG-Vocabolario: