國家信息保障認證和鑑定過程(NIACAP)角色與DITSCAP角色幾乎相同。進行NIACAP安全評估需要至少四個參與者(角色):
1. IS program manager (IS計劃經理):
- The IS program manager is the primary authorization advocate. He is responsible for the Information Systems (IS) throughout the life cycle of the system development.
- IS計劃經理是主要的授權倡導者。他負責系統開發整個生命週期中的信息系統(IS)。
2. Designated Approving Authority (DAA) 指定的批准機構(DAA):
- The Designated Approving Authority (DAA), in the United States Department of Defense, is the official with the authority to formally assume responsibility for operating a system at an acceptable level of risk.
- 美國國防部的指定的批准機構(DAA)是有權正式承擔以可接受的風險水平運行系統的責任的官員。
- The certification agent is also referred to as the certifier. He provides the technical expertise to conduct the certification throughout the system life cycle.
- 認證代理也稱為證明者。他提供技術專長以在整個系統生命週期內進行認證。
4. User representative (用戶代表):
- The user representative focuses on system availability, access, integrity, functionality, performance, and confidentiality in a Certification and Accreditation (C&A) process.
- 用戶代表專注於認證和鑑定(C&A)流程中的系統可用性,訪問權限,完整性,功能,性能和機密性。
* DITSCAP : Defense Information Technology Security Certification and Accreditation Program
國防信息技術安全認證與認可計劃
沒有留言:
張貼留言