范围(scoping)和裁剪(tailoring)两个术语关联场景相似,再加上经翻译后的语义误差,挺容易弄混的。
有标准就以标准定义为准咯,以下是从NIST SP 800-53中抄录的对应定义:
scoping considerations 范围的考虑因素
- A part of tailoring guidance that provides organizations with specific considerations on the applicability and implementation of security and privacy controls in the control baselines. Considerations include policy or regulatory, technology, physical infrastructure, system component allocation, public access, scalability, common control, operational or environmental, and security objective.
裁剪指南(tailoring guidance)的一部分,为组织提供了关于控制基线中安全性和隐私控制的适用性和实现的具体考虑。考虑因素包括政策或法规、技术、物理基础设施、系统组件分配、公共访问、可伸缩性、通用控制、操作或环境,以及安全目标。
tailored control baseline 已裁剪的(定制的)控制基线
- A set of controls that result from the application of tailoring guidance to a control baseline.
一组控制,它们是对控制基线应用裁剪指南(tailoring guidance)后的结果。
tailoring裁剪(量身定制)
- The process by which security control baselines are mod

最低0.47元/天 解锁文章
824

被折叠的 条评论
为什么被折叠?



