第1页共43页编号:时间:2021年x月x日书山有路勤为径,学海无涯苦作舟页码:第1页共43页芜湖市社保局信息安全解决方案第2页共43页第1页共43页编号:时间:2021年x月x日书山有路勤为径,学海无涯苦作舟页码:第2页共43页北京天融信科技有限公司2012年3月目录第一章项目背景··························41.1信息安全严峻形势······················41.2单位职能简介························5第二章安全风险分析························62.1风险分析方法························62.2网络安全弱点分析······················72.2.1网络结构脆弱性····················72.2.2系统和应用脆弱性···················82.2.3网络访问脆弱性···················102.2.4硬件平台脆弱性···················102.2.5管理脆弱性·····················102.3网络安全威胁分析·····················112.3.1威胁来源······················112.3.2非人为的安全威胁··················122.3.3人为的安全威胁···················122.4网络安全风险分析·····················152.4.1物理安全风险····················152.4.2终端安全风险····················152.4.3网络安全风险····················162.4.4系统安全风险····················172.4.5管理安全风险····················17第3页共43页第2页共43页编号:时间:2021年x月x日书山有路勤为径,学海无涯苦作舟页码:第3页共43页第三章建设需求分析························193.1自身安全防护的需求····················193.1.1互联网出口单点故障·················193.1.2对基础防护平台的需求················203.1.3对统一运维审计平台的需求··············213.1.4对集中安全管理的需求················213.1.5管理安全的需求···················223.2芜湖社保局的符合政策层面的需求··············22第四章整体方案设计························244.1方案设计原则·······················244.2信息安全规划图······················264.3规划内容简介·······················26第五章方案详细设计························275.1详细设计概述·······················275.2计算环境防护·······················275.2.1终端安全管理····················275.3安全边界防护·······················315.3.1防火墙部署·····················315.3.2网闸部署······················325.4保护通信网络·······················345.4.1负载均衡系统····················345.4.2安全运维审计····················375.5安全管理平台·······················395.5.1安全措施选择····················395.5.2安全措施整合····················405.5.3技术部署选择····················405.5.4安全策略设计····················415.5.5安全功能要求··················...