<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cloud &#38; Telecom Security &#187; IDC</title>
	<atom:link href="http://sbin.cn/blog/tag/idc/feed/" rel="self" type="application/rss+xml" />
	<link>http://sbin.cn/blog</link>
	<description>Technologies and comments on cloud and telecom security, bridging China and the world!</description>
	<lastBuildDate>Fri, 17 Feb 2012 06:43:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>True or False: 70% of security incidents are due to insider threats?</title>
		<link>http://sbin.cn/blog/2009/11/10/true-or-false-70-of-security-incidents-are-due-to-insider-threats/</link>
		<comments>http://sbin.cn/blog/2009/11/10/true-or-false-70-of-security-incidents-are-due-to-insider-threats/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 16:54:21 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-English-]]></category>
		<category><![CDATA[Architect]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[IDC]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[SecurityMetrics]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1491</guid>
		<description><![CDATA[Actually, the whole thread was originated with a message at discuss@securitymetrics.org &#8220;Request for ideas&#8221; by Dimitrios Stergiou. Dimitrios likes to have some recommendations for his master program. By a sudden idea, I dropped him a message to recommend him to work on this true or false problem at security metrics. It&#8217;s true or false: 70% [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2009/11/10/true-or-false-70-of-security-incidents-are-due-to-insider-threats/feed/</wfw:commentRss>
		<slash:comments>26</slash:comments>
		</item>
		<item>
		<title>[Chinese]漫谈IAM、AAA、AAAA</title>
		<link>http://sbin.cn/blog/2006/05/16/%e6%bc%ab%e8%b0%88iam%e3%80%81aaa%e3%80%81aaaa/</link>
		<comments>http://sbin.cn/blog/2006/05/16/%e6%bc%ab%e8%b0%88iam%e3%80%81aaa%e3%80%81aaaa/#comments</comments>
		<pubDate>Mon, 15 May 2006 16:57:00 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-Chinese-]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AAA]]></category>
		<category><![CDATA[AAAA]]></category>
		<category><![CDATA[Audit]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[IDC]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[信息安全]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/2006/05/16/%e6%bc%ab%e8%b0%88iam%e3%80%81aaa%e3%80%81aaaa/</guid>
		<description><![CDATA[或许A在网络信息安全这个领域中有点神秘色彩，也有些特殊地位。Authentication, Authorization, Account, Accounting, Audit, Availability, Accountability, Administration, 很多A，每个A都在A的名义下定义了不同的功能。 最早Cisco路由器配置中的AAA Newmodel，其中的AAA是指：Authentication, Authorization, and Accounting. 功能很明确，先作用户认证，然后授权他可以在设备上面进行什么样的操作，最后，进行记帐。对，这里的Accounting，就是记帐，不是帐号。它帮助运营单位对网络流量和操作进行记帐。 IDC中AAA的分类，定义了AAA，这里的AAA与Cisco网络设备配置中的AAA有所不同，区别点在于第三个A，IDC的AAA的第三个A是指 Administration, 其实含义基本上是除了Authentication认证，Authorization授权，以及Anti-virus反病毒、Firewall防火墙、 IDS入侵检测系统（在2000年以前，似乎IDS和扫描器都在这第三个A中，后来IDS单独分类统计）。现在IDC重新定义了AAA，将其分成了两个区域，第一是IAM(Identity and Access Management)，第二是SVM(Security Vulnerability Management)。参考下面的示意图，IAM中增加一个新内容，就是目录管理，SVM中也增加一点新内容，就是漏洞管理。漏洞扫描产品（scanners）本来也是属于IDC AAA中最后一个安全管理的内容，后来与IDS成为一个分支 ID&#38;A，现在漏洞管理的名义下重新回到SVM下面。当然了，今天的漏洞管理在内涵上大大超出了原来的单纯的漏洞扫描。 而AAAA则是国内领先运营商在AAA/IAM基础上结合国内的实践提出的模型，它的全称应该是: Account, Authentication, Authorization, Audit，也反映了中国安全业界对于安全管理的思索和创新。]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2006/05/16/%e6%bc%ab%e8%b0%88iam%e3%80%81aaa%e3%80%81aaaa/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

