首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 ISO/IEC 19678:2015
到馆阅读
收藏跟踪
购买正版
Information Technology — BIOS Protection Guidelines 信息技术 - BIOS保护指南
发布日期: 2015-04-22
ISO 19678:2015提供了防止未经授权修改PC客户端系统上的基本输入/输出系统(BIOS)固件的要求和指南。由于BIOS在PC体系结构中的独特和特权地位,恶意软件对BIOS固件的未授权修改构成了重大威胁。恶意的BIOS修改可能是针对组织的复杂的、有针对性的攻击的一部分?永久拒绝服务(如果BIOS损坏)或持续存在恶意软件(如果BIOS植入了恶意软件)。 如本出版物中所使用的,术语BIOS是指常规BIOS、可扩展固件接口(EFI)BIOS和统一可扩展固件接口(UEFI)BIOS。本国际标准适用于系统BIOS固件(例如。例如,常规BIOS或UEFI BIOS)存储在计算机系统的系统闪存中,包括可以格式化为选项ROM的部分。但是,它不适用于存储在计算机系统其他地方的选项ROM、UEFI驱动程序和固件。 子条款7.2为平台供应商提供了安全BIOS更新过程的要求。此外,子条款7.3提供了在操作环境中管理BIOS的指南。 虽然该国际标准侧重于当前和未来的x86和x64客户端平台,但控制和程序独立于任何特定的系统设计。
ISO 19678:2015 provides requirements and guidelines for preventing the unauthorized modification of Basic Input/Output System (BIOS) firmware on PC client systems. Unauthorized modification of BIOS firmware by malicious software constitutes a significant threat because of the BIOS's unique and privileged position within the PC architecture. A malicious BIOS modification could be part of a sophisticated, targeted attack on an organization?either a permanent denial of service (if the BIOS is corrupted) or a persistent malware presence (if the BIOS is implanted with malware). As used in this publication, the term BIOS refers to conventional BIOS, Extensible Firmware Interface (EFI) BIOS, and Unified Extensible Firmware Interface (UEFI) BIOS. This International Standard applies to system BIOS firmware (e.g., conventional BIOS or UEFI BIOS) stored in the system flash memory of computer systems, including portions that may be formatted as Option ROMs. However, it does not apply to Option ROMs, UEFI drivers, and firmware stored elsewhere in a computer system. Subclause 7.2 provides platform vendors with requirements for a secure BIOS update process. Additionally, subclause 7.3 provides guidelines for managing the BIOS in an operational environment. While this International Standard focuses on current and future x86 and x64 client platforms, the controls and procedures are independent of any particular system design.
分类信息
关联关系
研制信息
归口单位: ISO/IEC JTC 1
相似标准/计划/法规
现行
BS ISO/IEC 19678-2015
Information Technology. BIOS Protection Guidelines
信息技术 BIOS保护指南
2015-04-30
现行
INCITS TR-21-1999
Information Technology - Enhanced BIOS Services for Disk Drives
信息技术.磁盘驱动器的增强BIOS服务
1999-01-01
现行
INCITS TR-21-1999
Information Technology - Enhanced BIOS Services for Disk Drives
信息技术.磁盘驱动器的增强BIOS服务
1999-01-01
现行
INCITS 363-2002
Information technology - BIOS Enhanced Disk Drive Services - 2
信息技术.BIOS增强型磁盘驱动器服务.第2部分:
2002-09-16
现行
INCITS 363-2002
Information technology - BIOS Enhanced Disk Drive Services - 2
信息技术.BIOS增强型磁盘驱动器服务.第2部分:
2002-09-16
现行
ISO/IEC TS 27110-2021
Information technology, cybersecurity and privacy protection - Cybersecurity framework development guidelines
信息技术、网络安全和隐私保护.网络安全框架开发指南
2021-02-16
现行
BS PD ISO/IEC TS 27110-2021
Information technology, cybersecurity and privacy protection. Cybersecurity framework development guidelines
信息技术、网络安全和隐私保护 网络安全框架发展指南
2021-02-26
现行
GA/T 1389-2017
信息安全技术 网络安全等级保护定级指南
Information security technology—Guidelines for grading of classified protection of cyber security
2017-05-08
现行
NB/T 10680-2021
继电保护和安全自动装置信息安全技术导则
Guidelines for information security technology of relaying protection and safety automatic equipment
2021-04-26
现行
ISO/IEC TS 27110-2021
Information technology, cybersecurity and privacy protection — Cybersecurity framework development guidelines
信息技术、网络安全和隐私保护 网络安全框架发展指南
2021-02-16
现行
GB/Z 28828-2012
信息安全技术 公共及商用服务信息系统个人信息保护指南
Information security technology - Guideline for personal information protection within information system for public and commercial services
2012-11-05
现行
INCITS 407-2005
Information technology - BIOS Enhanced Disk Drive Services - 3 (EDD-3)
信息技术.BIOS增强型磁盘驱动器服务.第3部分(EDD-3)
2005-05-25
现行
INCITS 480-2011
Information Technology - BIOS Enhanced Disk Drive Specification - 4 (EDD-4)
信息技术.BIOS增强型磁盘驱动器规范.4(EDD-4)
2011-10-05
现行
INCITS 480-2011
Information Technology - BIOS Enhanced Disk Drive Specification - 4 (EDD-4)
信息技术.BIOS增强型磁盘驱动器规范.4(EDD-4)
2011-10-05
现行
INCITS 407-2005
Information technology - BIOS Enhanced Disk Drive Services - 3 (EDD-3)
信息技术.BIOS增强型磁盘驱动器服务.第3部分(EDD-3)
2005-05-25
现行
GOST R 53131-2008
Защита информации. Рекомендации по услугам восстановления после чрезвычайных ситуаций функций и механизмов безопасности информационных и телекоммуникационных технологий. Общие положения
信息保护 信息和通信技术安全功能和机制的恢复服务指南 一般
现行
ASIS GDL IAP-2007
Information Asset Protection Guideline
信息资产保护指南
现行
ASIS GDL IAP-2007
Information Asset Protection Guideline
信息资产保护指南
现行
GOST R 52447-2005
Защита информации. Техника защиты информации. Номенклатура показателей качества
信息保护 信息保护技术 质量指标命名
现行
GB/T 35287-2017
信息安全技术 网站可信标识技术指南
Information security technology—Guidelines of trusted identity technology for website
2017-12-29