Files
nexus/wiki/concepts/Three-Lines-of-Defense.md
2026-04-19 16:02:56 +08:00

43 lines
1.3 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: "Three Lines of Defense"
type: concept
tags: [Security, Governance, Risk-Management, Framework]
date: 2026-04-14
---
## Definition
三道防线Three Lines of Defense3LoD是一种企业风险管理框架通过分层职责确保安全控制的有效性。
## First Line of Defense
业务单元:负责在其领域内实施和管理安全控制,是安全的直接责任方。
## Second Line of Defense
集团办公室:负责制定政策、事件响应和网络工具,作为第一道防线的顾问,提供指导和支持。
## Third Line of Defense
审计:确保第一道和第二道防线的合规性,为企业提供保证。
## Key Drivers
- 监管合规Regulatory Compliance
- 集中化平台Centralized Platform
- 云迁移Cloud Migration
- 基线控制Baseline Controls
- 更大的安全响应覆盖范围
## Work Streams Implemented
- 政策审查与整合
- 事件响应参与
- 网络安全风险与控制指标开发
- 网络安全工具审查
- 安全架构标准与模式
## Related Entities
- [[Coyote]] — Head of Enterprise Application Security框架推动者
## Related Concepts
- [[Cloud-Security-Posture-Management]]
- [[Regulatory-Compliance]]
- [[Risk-Management]]
## Related Sources
- [[CTP Topic 52 3 Lines of Defence (3LoD) framework Cloud Security Posture Management (CSPM)]]