华为云网络安全等保 2.0 合规能力白皮书 V2.0
目 录
1 总述 ............................................................................................................................................ 1
2 目的 ............................................................................................................................................ 2
3 安全合规责任 ............................................................................................................................ 3
4 华为云安全合规与隐私保护能力模型 ...................................................................................... 6
4.1 保护对象 ............................................................................................................................................................. 6
4.2 安全措施 ............................................................................................................................................................. 6
4.3 安全能力 ............................................................................................................................................................. 8
4.3.1 云平台原生安全能力........................................................................................................................................ 8
4.3.2 云服务安全能力 ............................................................................................................................................... 8
4.3.3 云安全服务能力 ............................................................................................................................................... 9
4.3.4 云服务客户自建能力........................................................................................................................................ 9
4.4 安全合规评估 ...................................................................................................................................................... 9
4.5 隐私保护 ............................................................................................................................................................. 9
5 华为云对等保要求的解读 ....................................................................................................... 11
5.1 等级保护对象概述 ............................................................................................................................................. 11
5.2 等保基本合规要求分析(安全通用要求) .......................................................................................................12
5.2.1 安全物理环境 ..................................................................................................................................................12
5.2.2 安全通信网络 ..................................................................................................................................................12
5.2.3 安全区域边界 ..................................................................................................................................................16
5.2.4 安全计算环境 ..................................................................................................................................................25
5.2.5 安全管理中心 ..................................................................................................................................................43
5.2.6 安全管理制度 ..................................................................................................................................................49
5.3 等保基本合规要求分析(云计算安全扩展要求) ............................................................................................49
5.3.1 安全通信网络 ..................................................................................................................................................49
5.3.2 安全区域边界 ..................................................................................................................................................52
5.3.3 安全计算环境 ..................................................................................................................................................56
5.3.4 安全管理中心 ..................................................................................................................................................65
5.3.5 安全建设管理 ..................................................................................................................................................66
5.3.6 安全运维管理 ..................................................................................................................................................70