Professional Documents
Culture Documents
11 Avc
11 Avc
Chng I
Cu1: Hiu c tnh cp thit
* Ti sao cn quan tm n nh gi ATTT ngay t bc u tin:
- Nu khng nh gi ngay t u s nh hng ti doanh thu, uy tn
- Nu khng nh gi ngay t u s phi thit k, ch to li gy lng ph
- Khng khc phc c hu qu ca 1 sn phm khng tt, khng an ton
- nh thit k, nh sn xut xc nh c l c i ng hng khng
* Ti sao cn phi G ATTT
hiu v tnh cp thit, u tin ta phi v G ATTT
-GATTT theo ngha rng nht l q.trnh G mc AT ca TT cn c bo v di 3 yu cu AT
chnh
+Tnh b mt
+Tnh ton vn
+Tnh sn sng hot ng
-Mc u tin ty thuc vo mc ch s dng m mc u tin yu cu no
*Tnh cp thit
-ATTT lun c gn lin vi cc phng tin x l, lu tr v truyn tin
-Trc y cc phng tin nh vy thng n gin th s v ko c t ng ha. GATTT mi
ch hng ti cc HTCNTT ch cha phi SPCNTT
-Hin nay , cc phng tin CNTT c p.trin ngy cng nhiu v s lng, a dng v phc tp v
chc nng hot ng(phn mm, phn cng hay phn mm+phn cng kt hp, c cht b.v k.sot
hot ng TT). Do cn phi GAT i vi tng sp
-Khi s.dng cc p.tin CNTT trong cc hot ng CNTT ko nhng cn m bo cc chc nng m
cn cn m bo cc chc nng ATTT t ra cho chng.Nu sp ko m bo c mc ATTT th
khi em s.dng c th mang li nhng tn tht cc ln
-Mun bit sp CNTT c m bo mc ATTT mong mun hay ko th phi thng qua GATTT
c lng chnh xc mc ATTT ca sp
Thc t
-Q.trnh ton cu ha ko theo vic s.dng CNTT v Internet cng p.trin trn p.vi ton cu. Do
ATTT l nhim v ca ton TG
-Mng my tnh p.trin lm cho cc sp CNTT tng ln gp bi, phc tp v chc nng cng tng
ln=>m bo ATTT tr nn kh khn gp bi
-CNTT c s.dng hu ht trong tt c cc lnh vc nn cc e da ATTT ngy cng tng v c s
lng v mc
- n lc ko th chp nhn c sp CNTT em ra s.dng m ko c m bo ATTT .Ngay t
khu t.k, ch to phi c duy tr, k.sot trong sut thi gian hot ng cho ti khi ko cn c
lu hnh s dng
=>GATTT gn lin vi p.tch, t.k sp CNTT v php lut ATTT to thnh mt b ba tng th ATTT
nhm bo v TT mc cao nht c th c
Cu2.Cc thut ng v cc khi nim c bn
a.sp CNTT (Information technology products)
-L 1 s kt hp phn cng, phn mm, phn sn(firmware) cung cp 1 chc nng c t.k
s.dng hay kt hp s.dng trong HT CNTT
ST A
TOE A
ST B
TOE B
ST C
TOE C
PP
So snh gia PP v ST
*Ging:
Cng l tp hp cc yu cu p ng nhu cu ca khch hng
*Khc:
Trong PP dnh cho 1 chng loi sp cn ST th cho sp c th
Tt c cc yu cu ca ST phi xut pht t PP cn nhng yu cu ca PP th cha chc c p
ng ST.
*.ngha GATTT
(1):GATTT l vic nh gi PP, ch AT hay ch G tun theo nhng tiu ch ATTT c .n
(2):l vic G sp CNTT hay PP tun theo nhng y.cu ca nhng tiu ch ATTT
Cu3.Cc tiu ch G ca B Quc Phng M, Chu u, CANADA v lin bang M
a.Tiu ch G ca B Quc Phng M
-y l HT tiu ch ATCNTT u tin ca nhn loi , ra i vo t8/1983 bi BQP M vi tn gi l
TCSEC(Trusted Computer System Evaluation Criteria)
-Cc tiu ch trong TCSEC quan tm ti cc HT tin cy x.l d.liu t ng v thng mi hin hnh
- cp ti cc c tnh an ton v cc bin php m bo ti thiu i vi mi c t AT khc nhau
+Yu cu of c tnh nhm ti cc HT x.l TT da trn cc HH mc ch chung
+Y.cu c tnh AT c th p dng cho cc HT vi m.trng c bit nh cc b x.l hay cc my
tnh k.sot q.trnh lin lc
+Cc y.cu m bo c p dng cho tt c dng m.trng v HT tnh ton
-Mc ch ca cc y.cu ny v ca chnh cc tiu ch l hng ti 3 i tng
+Cung cp chun ATTT cho cc nh s.xut, gip nh sx bit TT ci t cc c tnh ATTT cho sp,
t p ng y.cu ca BQP
+Cho php BQP nh gi cng bng v chnh xc
+Cc G phi c x.nh cc HT m.trng c lp v m.trng c th.Trung tm AT quc
gia(National Security Center, NSC) s G sp i vi m.trng c lp theo cch ca q.trnh G sp
thng mi(CPEP-Commercial Product Evaluation Process). G tin cy v cc thuc tnh ca sp
thng qua m.trng vn hnh c th(G chng nhn)
>Cung cp c s ch r cc y.cu ATTT trong cc c t sp: X.nh mc ATTT m KH y.cu i
vi m.trng ca h
-Tiu ch a ra cc mc ch trn c chia thnh 4 phn on A,B,C,D. Mi phn on li
thnh cc phn on con(lp)
-Cc tiu ch xp loi sp thuc cc lp
+C.sch AT
+K ton hot ng
+m bo AT
+Lp ti liu
*Cc phn on
- Phn on D: Bo v ti thiu
+Cha 1 lp duy nht(lp D): Bo v ti thiu ginh cho cc HT c G v ko qua c cc y.cu
ca cc phn on t C-A
-Phn on C: Bo v phn quyn, cha 2 lp
+Lp C1: Bo v AT phn quyn ginh cho sp cung cp s bo v cn thit(phn quyn).iu ny
t c bng tch gia ngi s.dng v d.liu
+Lp C2: Bo v truy nhp c k.sot ginh cho cc sp m k.sot truy nhp mn hn cc sp trong
lp C1: t c vi cc th tc ng nhp v k.sot v c lp ti nguyn (ti nguyn tch hn vi
ngi s dng)
-Phn on B:bo v tp trung, gm 3 lp
+Lp B1:
>Bo v AT gn nhn
>Cha cc c tnh ca C2
>Y.cu gn nhn d.liu, k.sot truy cp tp trung trn cc ch th v cc i tng gn trn v tuyn
b ko hnh thc ca m hnh c.sch AT
+Lp B2:
>Bo v c cu trc
>Da trn lp B1
>Y.cu cng b hnh thc ca c.sch ATTT v hon thin tun th k.sot truy nhp phn quyn v
tp trung
>Tng cng c ch xc thc
>Phi cp n cc knh mt
=>B2 chng truy cp tri php
+Lp B3: Cc min AT
>y.cu nh B2
>Xp t cc hnh ng ca ngi s.dng
>Chng t nhp HT
>Cc c tnh AT cn cc k trng kin v trn tru
>Gi AT ko cn thm m c.trnh hay TT
>HT cn h tr ngi q.tr v k.ton cc th tc phc hi, d phng
=>B3 c kh nng cao chng li s truy cp tri php
-Phn on lp A: Bo v c kim tra
+Gm 1 lp A1: Thit k c k.tra
+Chc nng lp A1~ lp B3
+Tuy nhin, lp A1 thc hin trit tiu p.tch hnh thc hn l nhn thc c t t.k v k.tra hnh
thc ca cc c tnh AT
+P.tch ny phi cung cp mc m bo cao l HT c ci t ng n hn
* u im
-Quan tm ti cc tiu ch AT: c.sch AT , k ton h.ng, m bo AT, tnh hp l phn chia cc lp,
thng tin v cc knh mt v hng dn kim nh AT
-Hng ti x.dng HT tiu ch AT CNTT vn nng nhm ti ngi t.k, s dng v kim nh
-nh hng n cc HT ng dng quc phng c th l OS
+Tp trung vo cc y.cu bo mt TT c x.l loi tr kh nng lm l TT ny
+Quan tm nhiu n nhn AT v cc quy trnh xut thng tin bo mt
*Nhc im
-Cc tiu ch m bo thc hin ha cc p.tin bo v v c.sach an ton m nht
-Cha c s tch bit gia cc y.cu chc nng v m bo
-Cc y.cu k.sot tnh ton vn ca cc p.tin b.v v h tr tnh sn sng ca chng u ko y
-Kh chng minh c 1 sp c thuc lp AT A1 hay ko
b.Tiu ch g ca Chu u
- Nhm n nhu cu G ca sp thng mi v an ton chnh ph
-Phn tch khi nim mc G chc nng v m bo
-C 10 mc t F1 n F10. F1~C1(TCSEC), F5~A1(TCSEC), t F6 gn thm cc k.nim
m bo
E0
E1
E2
E3
E4
E5
E6
F1
F2
F3
F4
F5
F6
Function
Ensure
E0
E1
E2
E3
E4
E5
E6
F1
F2
F3
F4
F5
F5
*u im
-a ra khi nim tnh m bo v tch ring n vi tnh chc nng
*Nhc im
-Vn c nhng khim khuyt ngay trong cc HT c chng nhn trong cc tiu ch v kh nng
s.dng nhng khim khuyt trong bo v
c.Tiu ch G ca CANADA
-G tnh hiu qu cc d.v AT ca sp
-c t.k cho chnh ph s.dng m ko nhm ti cc sp thng mi
-Chia cc y.cu AT thnh 2 nhm: Chc nng v m bo
-Cc y.cu chc nng cha 4 phm tr chnh sch
+B mt
+Ton vn
+Sn sng
+K ton hot ng
-Cc y.cu m bo gm cc mc G t thp(T-0)n cao(T-7)
-Bao gm cc y.cu v: cu trc, m.trng p.trin, bng chng p.trin, m.trng vn hnh, lp ti
liu v kim nh
*u im
-Phn tch cc y.cu chc nng vi cc y.cu m bo v cht lng thc hin c.sch AT
-Cu trc cc y.cu chc nng r rng
-M t tt c cc kha cnh chc nng
-Phn chia c lp cc y.cu v m bo thc hin c.sach AT
-Quan tm nhiu n s tng ng ln nhau v tng ng ca tt c cc HT p.tin m bo AT
*Nhc im
-Cc y.cu v cng ngh t.k phn nh cn non yu
-Cc phng php v p.tin s.dng ko y chi tit ha
d.Tiu ch G lin bang M
*Mc tiu
-Bo v s u t hin hnh trong cng ngh AT
-Ci tin q.trnh G ang tn ti
-D kin i vi nhng cn thit thay i ca khch hng
-Thc y s ha hp quc t trong G AT CNTT
-a ra khi nim PP
+L 1 tp cc tiu ch x.nh 1 mc c th ca AT v tin cy i vi 1 sn phm cp
-PP gm cc thnh phn chc nng , m bo p.trin v G
+Chc nng:X.nh cc c tnh m sp phi h tr t.k p ng PP
+m bo p.trin: Quy nh mc m mi sp phi h tr thit k, k.sot v s.dng
+m bo G: Gm cc vn nh p.tch knh mt, kim nh ATTT
-nh ngha 3 nhm y.cu
+Chc nng:c cu trc tt v m t tt c cc kha cnh chc nng ca c s tnh ton tin cy
+Cng ngh t.k: nh thc cc nh s.xut s.dng cc cng ngh hin i ca lp trnh lm c s
cho vic khng nh li AT ca sp
+Q.trnh p.tch G: Mang tnh cch chung kh r v ko cha cc phng php lun c th v kim
nh v nghin cu AT SP CNTT
*u im
-S.dng s phn chia c lp cc y.cu ca mi nhm
-Xem xt n vic khc phc khuyt tt ca cc p.tin AT
-a ra k.nim PP
*Nhc im
-Phn tch y.cu m bo G v p.trin =>c nhiu s kt hp cc y.cu m bo=>c th to ra
nhiu h s tng t nhau=>s phc tp thi qu cho vic G v q.trnh phn loi mc
Cu4.nh gi AT Mt M
-Cc sp CNTT c th c cc module mt m
-G cc module mt m c lp vi GATTT : GATTT ch q.tm n vic p.tch G v s ci t
thc s v ng n ca cc module mt m
-1982 c chun LB M 1027(US federal Standard 1027), nh gi thit b mt m da trn DES.Sau
chuyn thnh FIPS PUB 140
-M v CANADA lin kt thit lp ra FIPS PUB 140-1nh chun G i vi cc module mt m
cho c 2 quc gia
10
11
12
+ m bo vn hnh:
-Cn cha min cho vn hnh ca TCB
- Cn m bo tnh ton vn h thng
+ m bo vng i:
- Cn kim nh nhng c ch AT
- Nhng c ch ny phi lm vic nhu cng b trong ti liu h thng
* Lp ti liu:
- C bn tiu ch con
+ Hng dn ngi s dng v c tnh AT:
- M t nhng c ch bo v c cung cp
- Hng dn cch dng cho ngi s dng
+Sch hng dn tin ch tin cy:
- a ra nhng cnh bo v chc nng v quyn hn cn c kim sot khi thc hin tin ch AT
-a ra nhng th tc kim tra v duy tr cc tp kim ton v cu trc bn ghi kim ton chi tit cho
mi kiu s kin kim ton
+ Lp ti liu kim nh: L ti liu m t:
- K hoch kim nh
- Th tc kim nh
- Kt qu kim nh
+ Lp ti liu thit k:
- M t trit l bo v ca ngi sn xut
- Gii thch cch chuyn trit l sang TCB
=> Tm li:
- Cc nguyn l chun C2 ch mang tnh cht tng qut, khng ch r v mt thc hnh
-Cn nhn bit kiu SP v h thng thng dng khi p dng mt mng my tnh c th
-Khng c nhng SP hon ton tun theo cc nguyn l ca chun C2
2.Nguyn l GSSP
-L mt tp hp nhng nguyn l thm nhp rng thc thi bo v thng tin
- Do y ban GSSP ca Hip hi AT cc h thng thng tin (ISSA) pht trin
- Lin quan n nhng c nhn qun l AT cc h thng thng tin hn l SP thng tin
-Cn ang bin ng
-Hin nay chng ta c: Phn cp cc nguyn l thnh ba mc:
+Nhng nguyn l thm nhp rng
+ Nhng nguyn l chc nng rng
+ Nhng nguyn l chi tit
a. Nguyn l thm nhp rng:
- nh ngha r rng, tha nhn k ton hot ng v quy trch nhim ATTT
b. Nguyn l nhn thc:
- Tt c nhng ngi c nhu cu cn bit c th truy cp n nhng nguyn l, nhng chun, nhng
quy nh hay nhng c ch ATTT v cc h thng thng tin v cn c thng tin v nhng e da
c th p dng i vi ATTT
c. Nguyn l v o c:
Thng tin cn c s dng v qun tr ATTT cn c thc hin mt cch c o c
d.Nguyn l nhiu bn: Nhng nguyn l, nhng chun, nhng quy nh v nhng c ch i vi
ATTT v cc h thng thng tin cn cp nhng xem xt v nhng quan im ca tt c cc bn
quan tm
13
e. Nguyn l t l: Nhng kim sot ATTT cn phi t l vi nhng ri ro sa i hay t chi s dng
hoc lm l thng tin
f.Nguyn l tch hp:
Nhng nguyn l, nhng chun, nhng quy nh v nhng c ch i vi ATTT cn phi c phi
hp v tch hp vi nhau v vi nhng chnh sch, nhng th tc ca t chc to ra v duy tr AT
trong ton h thng thng tin
g. Nguyn l kp thi:
Tt c cc bn c k ton hot ng cn hnh ng mt cch phi hp, kp thi ngn chn hoc
p tr nhng v phm hay e don n nhng ATTT v h thng thng tin
h. Nguyn l nh gi: Nhng ri ro n thng tin v h thng thng tin cn c nh gi nh k
i. Nguyn l cng bng: qun l cn phi tn trng nhng quyn v nhn phm ca mi c nhn khi
thit lp chnh sch v khi la chn, thc thi v bt buc tun th nhng bin php ATTT
Nhng nguyn l chc nng rng:
1. Chnh sch ATTT Qun l cn m bo rng chnh sch v nhwungx chun h tr, nhng vch
ranh gii, nhng th tc v nhng hng dn c pht trin
2.Nhn thc v gio dc: Qun l cn phi truyn t chnh sch ATTT n tt c i ng cn b v
m bo rng tt c nhn thc ph hp. Gio dc bao gm cc chun, nhng vch ranh gii,
nhng rhur tc, nhng hng dn
3. K ton hot ng: Qun l cn gi cho tt c cc bn c k ton hot ng i vi truy cp v
s dng ca h i vi thng tin nh trn, sa i, sao chp v xa v h tr nhng ngun ti
nguyn CNTT. Cn phi c kh nng ghi li ngy, gi v trch nhim n tn nhng c nhn i vi
tt c cc s ng ghi nh
4.Qun l thng tin: Qun l cn lp danh mc u n v nh gi nhng ti sn thng tin v ch
nh mc nhy cm v quan trng, Thng tin nh l ti sn cn phi c nh danh duy nht v
trch nhim i vi n phi c ch nh
5.Qun l mi trng: Qun l cn xem xt v n b nhng ri ro c h cho mi truonwg vn trong
v bn ngoi ni m nhng ti sn thng tin v nhng ta nguyn h tr CNTT v ti sn c lu
tr, truyn hay s dng
6.Trnh i ng cn b: Qun l cn thit lp v kim tra trnh lin quan n tnh ton vn, cn
th mi bit v nng lc k thut ca tt c cc bn c truy cp n ti sn thng tin hay ti
nguyn h tr CNTT
7.Ton vn h thng: qun l cn m bo rng tt c nhng tnh cht ca cc h thng v cc c
trng
8.Vng i ca cc h thng thng tin: Qun l cn m bo rng AT hng n tt c cc giai on
ca vng i ca h thng
9. Kim sot truy cp qun l:
10.K hoch i ph bt trc v tnh lin tc vn hnh
11.qun l ri ro thng tin
12.AT h tng c s v AT mng
13.Yu cu hp ng, php l v quy nh ca ATTT
14.Nhng thc hnh o c.
3.Nhng nguyn l an ton c th(chi tit)
C nhiu nguyn l h tr 1 hay nhiu nguyn l chc nng m rng.
Chng III
14
15
16
+H tr vng i
+cc php kim nh
+nh gi tn thng
=>+Cc yu cu EAL
+cc yu cu mi
+cc yu cu m bo AT ch yu
+cc yu cu m bo AT h tr
+phn cp tng ln ca mi thnh phn
*Cc mc
EAL1:Mc m bo an ton c kim nh chc nng
EAL2:Mc m bo an ton c kim nh cu trc
EAL3:Mc m bo an ton c kim nh v kim tra c phng php
EAL4:Mc m bo an ton c thit k, kim nh v duyt li c phng php
EAL5:Mc m bo an ton c thit k v kim nh bn hnh thc
EAL6:Mc m bo an ton c kim nh v thit k c thm nh bn hnh thc
EAL7:Mc m bo an ton c kim nh v thit k c thm nh hnh thc, mc ny th hin
kim nh hp trng
Cu 3: Phn bit PP&ST
a. PP
-L ti liu hnh thc phn nh mt tp c lp vi ci t ca nhng yu cu an ton c v chc
nng v m bo i vi sn phm hay h thng CNTT p ng nhng nhu cu c th ca khch
hng
-Qu trnh pht trin h s bo v hng dn khch hng lm sng t, xc nh v xc nhn tnh hp
l nhng yu cu an ton ca h=>KQ cui cng c s dng chuyn ti nhng yu cu ny n
cc nh sn pht trin tim nng v cung cp c s pht trin ch an ton v nh gi hnh thc
i vi sn phm
-Mc ch ca PP :
+Pht biu bi ton an ton mt cch cht ch i vi mt tp hay mt b cho ca cc h thng
hay sp CNTT chnh l ch nh gi
+Ch r nhng yu cu an ton hng n bi ton nhng ko ch r xem nhng yu cu ny s ci
t nh th no
b. ch an ton
-L mt s hng ng ph thuc vo ci t i vi mt PP
+PP ch c t nhng yu cu chc nng v m bo an ton
+ST cung cp mt thit k chi tit m khi n kt hp vi nhng c ch an ton chc nng v nhng
tiu chun m bo an ton c th s hon thnh c nhng yu cu ny
-nh gi ST tp trung vo vic kim tra xem n c din gii ph hp , chnh xc, y v hon
thin hay k ca nhng yu cu trong PP
-ST c vit ra bi nh pht trin sn phm nhm hng ng mt PP v c c bi nhng khch
hng tim nng v c kim duyt bi nh nh gi
Chng IV
Cu 1: Hiu c bn cht ca CEM
Tr li
CEM(Common Evaluation Methodogy-Phng php lun nh gi chung)
-CEM cung cp hng dn c th cho ngi nh gi
17
18
19
20
21
Gi nh a mm b v hiu ha
3.
22
23
24
+G s th hin ph hp
*ADV-FSP.1: Xc nh xem ngi ptrin cung cp m t y cc chng nng AT ca TOE
cha v liu cc chc nng AT c ph hp tho mn cc yu cu chc nng AT ca ST k
-u vo:ST, c t chc nng, hng dn ngi s dng, hng dn ngi qun tr
+1:ADV-FSP.1-1: Kst c t chc nng xc nh xem n c cha ti liu ko hnh thc cn thit
gii thch ko
+1:ADV-FSP.1-2:Kst xc nh xem n c ph hp vi ni ti k
+1:ADV-FSP.1-3:Kst c t chc nng->xc nh xem n c nhn ra tt c cc giao din chc nng
AT TOE bn ngoi ko
+1:ADV-FSP.1-4:Kst c t chc nng->xc nh xem n ch nhn ra tt c cc giao din chc
nng AT TOE bn ngoi ko
+1:ADV-FSP.1-5:Kst c t giao din chc nng AT TOE xc nh xem n c miu t y v
chnh xc hot ng ca TOE ti mi giao din bn ngoi m miu t cc hat jg ngoi tr cc
thng ip bo li k
*ADV-FSP.1.2E
+ADV-FSP.1-7:Kst c to chc nng->xc nh n c l v d c th y ca cc yu cu chc
nng AT TOE k
*Hot ng con g s th hin ph hp: Xc nh xem ngi p.trin ci t y v ng n
cc yu cu ca ST trong c t chc nng cha
-u vo: ST, c t chc nng, phn tch s ph hp gia c t tm tt TOE v c t chc nng
Chng V:
Cu 1: Hiu c tm quan trng ca h tng c s nh gi
a. Xy dng c s h tng c s nh gi:
Mun tin hnh G ATTT cn c c s h tng G ATTT iu kin
Mi quc gia nn XD cc mi quan h
- Cn xc nh vai tr v trch nhim ca cc bn tham gia vo hot ng G ATTT s dng
CC/CEM
+ Khch hng, ngi pht trin, ngi G ngi bn SP CNTT, nh ti tr, phng th nghim
kim nh tiu ch chung (CCTL), nh thm quyn G quc gia (NEA), ban qun l thi hnh tiu ch
chung (CCIMB)
- Trc tin mi quc gia cn ban hnh lut v khung php l cho php tin hnh G ATTT v
nhng vn lin quan
- Ban hnh cc qui nh, php lnh v nhng hng dn quy nh thi hnh c th ca tt c cc lnh
vc lin quan n G ATTT
b. H tng c s tiu chun o lng:
- L nhng c quan nh nc chu trch nhim v tiu chun o lng i vi cc sp, thit b, linh
kin KH, KT v CN
c. H tng c s c cu t chc:
- C quan bao trm tt c hot ng G ATTT CNTT ca mt quc gia l NEA
+ Di l cc c quan tin hnh hot ng G/ cp chng nhn SP CNTT
C quan nh gi (Evaluation Agency)
C quan cp chng nhn
C quan chnh sch (Policy Agency)
- Ngi nh gi v pht trin phi c kin thc chuyn su v ATTT nht l G ATTT s dng CC
v CEM
- Ring ngi pht trin phi c kin thc chuyn su v pht trin h thng v phn mm ATTT
25
26
+Ngi thm nh hp l NIAP lp ti liu cc kt qu G AT CNTT khi cng vic ang tin hnh
+CCTL hon thnh G v trnh ETR cho NEA v nh ti tr
+NEA thm nh ETR khng nh thm nh hp l c th c tip tc
- u ra:
+Cc OR
+Cc bo co tm tt hng thng
+Bng G gi cng vic
+Cc bn ghi gi cng vic G
+ETR
c.Pha th 3-KQ G
-u vo: ETR cui cng
-Tc v
+NEA thm nh ETR cui cng, cp nhng quan tm/vn vi CCTL
+Nh ti tr v CCTL thm nh bn tho bo co xc nhn hp l(VR), cung cp nhng nhn xt
cho NEA
+NEA cng b VR cui cng v cp pht chng nhn CC
+Mt tinh sau khi xc nhn hp l
-u ra
+D tho VR
+VR cui cng
+Chng nhn CC
+Cc mc ghi tn trong danh sch sp chng nhn EPL
+Bo co cc bi hc c rt ra
d.Pha th 4-Duy tr m bo G
-Gm 3 tiu pha: Chp thun, gim st v G li
*Chp thun
-u vo :ST v TOE
-Tc v
+Nh ti tr y.cu c vo chng tnh duy tr chng nhn CMP ti thi im bt u ca khi u
G
+Nh ti tr trnh k hoch duy tr m bo AMP v ti liu lin quan n CCTL, ch nh nh
phn tch AT ca nh pht trin
+CCTL G AMP v ti liu lin quan nh mt phn ca khi u G
+CCTL trnh ETR
*Gim st
-u vo:
+Nhng thay i c ngh
+Bo co G nh hng AT SIA
-Tc v
+Nh ti tr trnh nhng thay i c ngh n NEA
*G li
-Quay tr li qu trnh nh gi ban u
2. G NIACAP
- National Information Assurance Certification and Accreditation Process: Quy trnh chng nhn v
tn nhim m bo thng tin quc gia c sd bi BQP M
- Mc tiu:
+ Chng nhn HTTT (IS) tha mn cc yc AT nu trong TL
27
28
29