跳到主要导航 跳到搜索 跳到主要内容

A Reference Model for Information Security of Information and Communication Technology Product Supply Chain

  • Liangyu Dong
  • , Sheng Hong*
  • , Jianing Zhao
  • , Jiacheng Wang
  • , Yang Li*
  • *此作品的通讯作者
  • Response Team
  • Beihang University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Information and Communication Technology (ICT) products are becoming increasingly important in people's daily lives, and cyberspace security issues caused by ICT supply chains have attracted widespread attention. This paper reflects that, even while various contributions were made towards the construction of information security frameworks, there appears still to be an absence of an explicit reference model. The choice of research subject here is ICT supply chains, in which a reference security model framework for cyberspace security of ICT supply chains is discussed. The reference model developed is based on the application of the NIST information security reference model methodology. Conducting a thorough analysis of ICT supply chain structure and information security risk, we categorize the various kinds of information security attacks on ICT supply chain and catalog them on the security target reference model. This developed model of reference information security shall serve as an excellent articulation of how to boost the confidentiality, integrity, and availability of systems design, analysis, and verification to specific attack types through hacking. Therefore, the research methodology described herein is equally appropriate and transferrable for the information security studies of other information systems. Hence, the reference model framework proposed in this research may play an important role in fields related to information security and may promote the development of effective countermeasures against ICT supply chain attacks.

源语言英语
主期刊名Proceedings - 2025 3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025
出版商Institute of Electrical and Electronics Engineers Inc.
109-114
页数6
ISBN(电子版)9798331535858
DOI
出版状态已出版 - 2025
活动3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025 - Dongguan, 中国
期限: 11 4月 202514 4月 2025

出版系列

姓名Proceedings - 2025 3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025

会议

会议3rd International Conference on Mobile Internet, Cloud Computing and Information Security, MICCIS 2025
国家/地区中国
Dongguan
时期11/04/2514/04/25

指纹

探究 'A Reference Model for Information Security of Information and Communication Technology Product Supply Chain' 的科研主题。它们共同构成独一无二的指纹。

引用此