On the contrary , this thesis presents an brand - new information system security assurance system model that should be based on the security strategy , people as the acting role , security technology as the body to support the implementation of security engineering system , safety management as a means to the relevant standards , laws and regulations as a guarantee , roundly and effectively to protect information systems security 接下來,本文具體研究了構(gòu)成安全保障體系的各要素,分別分析了信息安全策略、安全組織(人) ,安全工程過程(技術(shù)) ,安全管理以及相關(guān)的標準、法律法規(guī)。尤其重點介紹了安全工程過程(技術(shù))的保障,以及安全管理的保障。