系统之家提供 Windows 系统、Ghost 系统、驱动与常用软件的安全下载及安装教程。纯净系统 原版ISO 微软官方镜像 MSDN我告诉你 系统之家 装机吧 小白一键重装 驱动总裁 万能驱动 启动盘制作 Rufus Ventoy UltraISO PE系统 微PE 进BIOS 设置U盘启动 分区工具 DiskGenius 格式化C盘 激活工具 KMS 正版授权 系统补丁 运行库 DirectX VC++ .NET Framework 安全设置 系统优化 备份还原 后台管理
📢 欢迎访问系统之家!所有资源均经过安全检测。

SANS VulnOps Guide for CISOs and Leaders

发布时间:2026-09-13 | 浏览:1
📥 下载地址(文章开头)
装机神器安装一切系统。
376,545 followers Report this post Tomorrow, SANS goes live on VulnOps: A CISO's Guide to Starting Implementation, a 30-minute Rapid Briefing from Ed Skoudis , President of the SANS Technology Institute , and SANS faculty and staff. Worth the half hour: a green remediation dashboard measures how fast tickets close, not how much exploitable exposure is still live in the environment, or for how long. AI-assisted discovery is surfacing vulnerabilities faster than a find-score-patch workflow can absorb, and the gap between dashboard-green and actually-exposed keeps widening. The briefing lays out what a VulnOps operating model does differently: prioritizing remediation by business risk and exploitability instead of raw CVSS, a patch-decision loop that routes systems to auto-patch, test-first, or manual review without slowing the team down, and a defensible way to bring the funding and governance conversation to the board. For CISOs, security executives, and vulnerability management leaders. Free. Live. No registration required. Report this comment 📌 Watch the livestream: https://www.linkedin.com/events/7485690683190693888 #VulnOps #CISO To view or add a comment, sign in More Relevant Posts Marc-Aurele Stark 1mo Report this post Every consequential technology earned trust the same way: independent testing against a public standard. Electricity got UL. Cars got crash tests. AI agents that write production code are that consequential now. Code they generate runs in banks, hospitals, and critical infrastructure. Cursor put its agent through thousands of adversarial scenarios (secrets leakage, hidden prompt injection, insecure code defaults) and an independent Schellman audit against AIUC-1 . One of the most-used coding agents in the world chose to be tested before anyone required it. Congrats to the Cursor team! Cursor 468,436 followers 1mo Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 24 2 Comments Like Comment Share Copy LinkedIn Facebook X To view or add a comment, sign in Report this post Every consequential technology earned trust the same way: independent testing against a public standard. Electricity got UL. Cars got crash tests. AI agents that write production code are that consequential now. Code they generate runs in banks, hospitals, and critical infrastructure. Cursor put its agent through thousands of adversarial scenarios (secrets leakage, hidden prompt injection, insecure code defaults) and an independent Schellman audit against AIUC-1 . One of the most-used coding agents in the world chose to be tested before anyone required it. Congrats to the Cursor team! 468,436 followers Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 To view or add a comment, sign in Venkat Raghavan 4w Report this post Cursor is now AIUC-1 certified — and Lovable earned it too, the first two coding agent platforms to do so. But what does this mean? Let's unpack. There are two entities here. First, the agent platform, which is Cursor, built on top of an underlying model. Second, the agents built using Cursor, owned by enterprises. Therefore there are two separate questions enterprises need to answer. Question 1: How do enterprises assess model safeguards? Model safeguards are fallible. Time and again their safeguards have been bypassed, or in some cases models become adversaries — like with OpenAI and Hugging Face, and a slew of other model-related incidents. Here, Cursor's independent audit means they've been evaluated against AIUC-1. That provides some measure of confidence for enterprises evaluating coding agent platforms. Question 2: The far more important question — can I assume coding agents built using Cursor or other agent coding platform are safe, trustworthy, and secure? Here the answer is no. Agents are probabilistic systems. The actions they take are non-deterministic. The real question isn't whether the generated code is insecure. It's what actions the code is taking when it executes. Are these tools authorized? Are these actions authorized? Are they safe? Are they operating within their scope and intent? If they're veering off intent, how do I have human oversight over it? These are runtime controls. This is the responsibility of the enterprise. This is not addressed by this certification. Bottomline — it's good that agent and model safeguards are going through independent audit. But enterprises are accountable for what their agents do, and for governing their enterprise alpha, regardless of which agent platform or model they choose. Agent actions are structurally non-deterministic — no audit changes that. That accountability can't be outsourced to a certification. Runtime controls are how enterprises hold it themselves — a trusted governance process that sits outside the reasoning process or agent harness. That's what LangGuard.AI brings — the missing runtime controls for Cursor and Lovable users. #AgentSecurity #AIGovernance #RuntimeControls #AIUC1 #LangGuard Cursor 468,436 followers 1mo Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 5 Like Comment Share Copy LinkedIn Facebook X To view or add a comment, sign in Report this post Cursor is now AIUC-1 certified — and Lovable earned it too, the first two coding agent platforms to do so. But what does this mean? Let's unpack. There are two entities here. First, the agent platform, which is Cursor, built on top of an underlying model. Second, the agents built using Cursor, owned by enterprises. Therefore there are two separate questions enterprises need to answer. Question 1: How do enterprises assess model safeguards? Model safeguards are fallible. Time and again their safeguards have been bypassed, or in some cases models become adversaries — like with OpenAI and Hugging Face, and a slew of other model-related incidents. Here, Cursor's independent audit means they've been evaluated against AIUC-1. That provides some measure of confidence for enterprises evaluating coding agent platforms. Question 2: The far more important question — can I assume coding agents built using Cursor or other agent coding platform are safe, trustworthy, and secure? Here the answer is no. Agents are probabilistic systems. The actions they take are non-deterministic. The real question isn't whether the generated code is insecure. It's what actions the code is taking when it executes. Are these tools authorized? Are these actions authorized? Are they safe? Are they operating within their scope and intent? If they're veering off intent, how do I have human oversight over it? These are runtime controls. This is the responsibility of the enterprise. This is not addressed by this certification. Bottomline — it's good that agent and model safeguards are going through independent audit. But enterprises are accountable for what their agents do, and for governing their enterprise alpha, regardless of which agent platform or model they choose. Agent actions are structurally non-deterministic — no audit changes that. That accountability can't be outsourced to a certification. Runtime controls are how enterprises hold it themselves — a trusted governance process that sits outside the reasoning process or agent harness. That's what LangGuard.AI brings — the missing runtime controls for Cursor and Lovable users. #AgentSecurity #AIGovernance #RuntimeControls #AIUC1 #LangGuard 468,436 followers Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 To view or add a comment, sign in Yanina Dueri Valdivieso, CISA 3w Report this post 🤖 🔜 Traditional SOC 2 reports were built for predictable, deterministic software. AI agents are anything but. The enterprise AI landscape has often felt a bit like building a skyscraper without a blueprint—we all see the massive potential, but the foundational controls have been lagging behind the hype. I’ve recently been digging into AIUC-1, the newly launched AI agent standard co-created by a consortium of 100+ Fortune 500 CISOs and security leaders. To put it in auditor speak: think of it as an evolved SOC 2 designed specifically for AI agents that intake, transform, and report on sensitive financial information. It’s an interesting attempt to standardize the ethical and responsible use of autonomous systems. Here are my takeaways and predictions on how this shapes our industry: 1️⃣ The Regulatory Stopgap: Over 1,000 AI-related bills were introduced in U.S. state legislatures in 2025 alone. While global lawmakers scramble to align, frameworks like AIUC-1 are stepping in to provide the unified benchmark for data integrity and investor peace of mind that the C-suite desperately needs today. 2️⃣ A New Standard for Risk Transfer: What caught my eye is their "confidence infrastructure" model. AIUC-1 pairs technical certification with up to $50M in insurance coverage for AI-specific failures (like hallucinations, IP infringement, or tool call errors). From a vendor due diligence perspective, pairing technical attestation with actual indemnification is a compelling evolution. 3️⃣ The Auditor’s Reality Check: But let's put our auditor hats on for a second. AI is inherently non-deterministic. Certifying against hallucinations or logic failures today doesn't guarantee a model won't drift next month. While AIUC-1 updates its framework quarterly to keep pace, implementing this will require organizations to shift from comfortable, annual "check-the-box" audits to continuous, dynamic compliance monitoring. The framework is great, but the execution will be heavy. AI governance is no longer a "next year" problem; it is the new baseline. We have to prove to our clients, staff, and investors that we aren't just innovating, but innovating securely. ❓I'm curious to hear from my network: Are we ready to trust autonomous AI agents with our core business workflows, or is the technology still moving faster than our ability to secure it? Let me know how your teams are handling AI vendor risk below. 👇 #ArtificialIntelligence #AIGovernance #CyberSecurity #RiskManagement #Audit #Compliance #FutureOfWork #CISO #TechTrends #Innovation #AIUC Cursor 468,436 followers 1mo Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 2 4 Comments Like Comment Share Copy LinkedIn Facebook X To view or add a comment, sign in Report this post 🤖 🔜 Traditional SOC 2 reports were built for predictable, deterministic software. AI agents are anything but. The enterprise AI landscape has often felt a bit like building a skyscraper without a blueprint—we all see the massive potential, but the foundational controls have been lagging behind the hype. I’ve recently been digging into AIUC-1, the newly launched AI agent standard co-created by a consortium of 100+ Fortune 500 CISOs and security leaders. To put it in auditor speak: think of it as an evolved SOC 2 designed specifically for AI agents that intake, transform, and report on sensitive financial information. It’s an interesting attempt to standardize the ethical and responsible use of autonomous systems. Here are my takeaways and predictions on how this shapes our industry: 1️⃣ The Regulatory Stopgap: Over 1,000 AI-related bills were introduced in U.S. state legislatures in 2025 alone. While global lawmakers scramble to align, frameworks like AIUC-1 are stepping in to provide the unified benchmark for data integrity and investor peace of mind that the C-suite desperately needs today. 2️⃣ A New Standard for Risk Transfer: What caught my eye is their "confidence infrastructure" model. AIUC-1 pairs technical certification with up to $50M in insurance coverage for AI-specific failures (like hallucinations, IP infringement, or tool call errors). From a vendor due diligence perspective, pairing technical attestation with actual indemnification is a compelling evolution. 3️⃣ The Auditor’s Reality Check: But let's put our auditor hats on for a second. AI is inherently non-deterministic. Certifying against hallucinations or logic failures today doesn't guarantee a model won't drift next month. While AIUC-1 updates its framework quarterly to keep pace, implementing this will require organizations to shift from comfortable, annual "check-the-box" audits to continuous, dynamic compliance monitoring. The framework is great, but the execution will be heavy. AI governance is no longer a "next year" problem; it is the new baseline. We have to prove to our clients, staff, and investors that we aren't just innovating, but innovating securely. ❓I'm curious to hear from my network: Are we ready to trust autonomous AI agents with our core business workflows, or is the technology still moving faster than our ability to secure it? Let me know how your teams are handling AI vendor risk below. 👇 #ArtificialIntelligence #AIGovernance #CyberSecurity #RiskManagement #Audit #Compliance #FutureOfWork #CISO #TechTrends #Innovation #AIUC 468,436 followers Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 To view or add a comment, sign in Arun Sivadasan 1mo Edited Report this post AIUC-1 certification is gaining in adoption. Cursor is the latest one... good potential to be as popular as SOC 2 in the AI world. I had briefly covered this certification in: https://lnkd.in/d2K2Ta9n Cursor 468,436 followers 1mo Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 3 Like Comment Share Copy LinkedIn Facebook X To view or add a comment, sign in Report this post AIUC-1 certification is gaining in adoption. Cursor is the latest one... good potential to be as popular as SOC 2 in the AI world. I had briefly covered this certification in: https://lnkd.in/d2K2Ta9n 468,436 followers Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 To view or add a comment, sign in Ali Rowghani 1mo Report this post Very happy to see more companies like Cursor adopt a common standard for AI agent security. This is an important development to make sure innovation in AI stays safe for customers and for the world. Cursor 468,436 followers 1mo Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 23 Like Comment Share Copy LinkedIn Facebook X To view or add a comment, sign in Report this post Very happy to see more companies like Cursor adopt a common standard for AI agent security. This is an important development to make sure innovation in AI stays safe for customers and for the world. 468,436 followers Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 To view or add a comment, sign in
📥 下载地址(文章中间)
装机神器安装一切系统。
Cursor 468,436 followers 1mo Report this post Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 1,056 34 Comments Like Comment Share Copy LinkedIn Facebook X To view or add a comment, sign in 468,436 followers Report this post Cursor is now AIUC-1 certified. AIUC-1 offers a strong standard for AI agent security, safety, and reliability, developed with a consortium of more than 250 CISOs & risk leaders from the Fortune 500. As part of the certification, Schellman, the first accredited AIUC-1 auditor, independently reviewed our controls and governance practices. Our agents also went through adversarial testing across thousands of scenarios, and our safeguards held across those evaluations. Read more: cursor.com/blog/aiuc-1 To view or add a comment, sign in Omar Eldeeb 1w Report this post 🚨 The Vulnerability Gap is Widening: Discovery is Outrunning Repair 🔍 Discovery velocity is surging — automated scanning, AI-driven attack tools, and bug bounty programs are surfacing vulnerabilities faster than most teams can triage, let alone fix. ⚠️ Patch timelines are buckling under pressure — mean time to remediate is stretching well beyond risk tolerance thresholds, leaving critical systems exposed for weeks, not days. 🔄 The remediation bottleneck isn't just technical — organizational friction, legacy dependencies, and change-management fear are silently compounding the backlog. 🎯 Risk prioritization is failing — teams still chase CVSS scores instead of exploiting context, burning cycles on theoretical threats while known-exploited vulnerabilities linger in production. 📉 The trust deficit is growing — every patching delay widens the gap between security promises and operational reality, eroding confidence among customers, partners, and regulators. The real question isn't whether we can discover more vulnerabilities — it's whether we can fundamentally rethink remediation as a continuous, risk-driven capability rather than a reactive fire drill. What's actually blocking your organization from closing this gap? Link: https://lnkd.in/euxYRRnQ 1 Like Comment Share Copy LinkedIn Facebook X To view or add a comment, sign in Report this post 🚨 The Vulnerability Gap is Widening: Discovery is Outrunning Repair 🔍 Discovery velocity is surging — automated scanning, AI-driven attack tools, and bug bounty programs are surfacing vulnerabilities faster than most teams can triage, let alone fix. ⚠️ Patch timelines are buckling under pressure — mean time to remediate is stretching well beyond risk tolerance thresholds, leaving critical systems exposed for weeks, not days. 🔄 The remediation bottleneck isn't just technical — organizational friction, legacy dependencies, and change-management fear are silently compounding the backlog. 🎯 Risk prioritization is failing — teams still chase CVSS scores instead of exploiting context, burning cycles on theoretical threats while known-exploited vulnerabilities linger in production. 📉 The trust deficit is growing — every patching delay widens the gap between security promises and operational reality, eroding confidence among customers, partners, and regulators. The real question isn't whether we can discover more vulnerabilities — it's whether we can fundamentally rethink remediation as a continuous, risk-driven capability rather than a reactive fire drill. What's actually blocking your organization from closing this gap? Link: https://lnkd.in/euxYRRnQ To view or add a comment, sign in Gil Kremer 1w Report this post “Everything looks critical.” When security teams cannot connect vulnerabilities, network exposure, and business impact, the remediation queue loses meaning. I use three questions to bring context back into the decision: 1. Is the exposure actually reachable? 2. Which application or business service depends on that path? 3. What operational or business impact could result? Customer proof in the workbook reinforces the value of this context. Centralized visibility, traffic flow analysis, and multi-vendor support were cited as key reasons for selecting AlgoSec . My takeaway: risk prioritization improves when security data is organized around applications and business impact, with rule-level details supporting that larger context. In a hybrid environment, application context gives engineers, architects, and executives a shared way to decide what deserves action first. What context most often changes your remediation priority? 3 Like Comment Share Copy LinkedIn Facebook X To view or add a comment, sign in Report this post “Everything looks critical.” When security teams cannot connect vulnerabilities, network exposure, and business impact, the remediation queue loses meaning. I use three questions to bring context back into the decision: 1. Is the exposure actually reachable? 2. Which application or business service depends on that path? 3. What operational or business impact could result? Customer proof in the workbook reinforces the value of this context. Centralized visibility, traffic flow analysis, and multi-vendor support were cited as key reasons for selecting AlgoSec . My takeaway: risk prioritization improves when security data is organized around applications and business impact, with rule-level details supporting that larger context. In a hybrid environment, application context gives engineers, architects, and executives a shared way to decide what deserves action first. What context most often changes your remediation priority? To view or add a comment, sign in Gil Kremer 1w Report this post “Everything looks critical.” When security teams cannot connect vulnerabilities, network exposure, and business impact, the remediation queue loses meaning. I use three questions to bring context back into the decision: 1. Is the exposure actually reachable? 2. Which application or business service depends on that path? 3. What operational or business impact could result? Customer proof in the workbook reinforces the value of this context. Centralized visibility, traffic flow analysis, and multi-vendor support were cited as key reasons for selecting AlgoSec . My takeaway: risk prioritization improves when security data is organized around applications and business impact, with rule-level details supporting that larger context. In a hybrid environment, application context gives engineers, architects, and executives a shared way to decide what deserves action first. What context most often changes your remediation priority? 1 Like Comment Share Copy LinkedIn Facebook X To view or add a comment, sign in Report this post “Everything looks critical.” When security teams cannot connect vulnerabilities, network exposure, and business impact, the remediation queue loses meaning. I use three questions to bring context back into the decision: 1. Is the exposure actually reachable? 2. Which application or business service depends on that path? 3. What operational or business impact could result? Customer proof in the workbook reinforces the value of this context. Centralized visibility, traffic flow analysis, and multi-vendor support were cited as key reasons for selecting AlgoSec . My takeaway: risk prioritization improves when security data is organized around applications and business impact, with rule-level details supporting that larger context. In a hybrid environment, application context gives engineers, architects, and executives a shared way to decide what deserves action first. What context most often changes your remediation priority? To view or add a comment, sign in Apoorv Singh 1w Report this post “Everything looks critical.” When security teams cannot connect vulnerabilities, network exposure, and business impact, the remediation queue loses meaning. I use three questions to bring context back into the decision: 1. Is the exposure actually reachable? 2. Which application or business service depends on that path? 3. What operational or business impact could result? Customer proof in the workbook reinforces the value of this context. Centralized visibility, traffic flow analysis, and multi-vendor support were cited as key reasons for selecting AlgoSec . My takeaway: risk prioritization improves when security data is organized around applications and business impact, with rule-level details supporting that larger context. In a hybrid environment, application context gives engineers, architects, and executives a shared way to decide what deserves action first. What context most often changes your remediation priority? 4 Like Comment Share Copy LinkedIn Facebook X To view or add a comment, sign in Report this post “Everything looks critical.” When security teams cannot connect vulnerabilities, network exposure, and business impact, the remediation queue loses meaning. I use three questions to bring context back into the decision: 1. Is the exposure actually reachable? 2. Which application or business service depends on that path? 3. What operational or business impact could result? Customer proof in the workbook reinforces the value of this context. Centralized visibility, traffic flow analysis, and multi-vendor support were cited as key reasons for selecting AlgoSec . My takeaway: risk prioritization improves when security data is organized around applications and business impact, with rule-level details supporting that larger context. In a hybrid environment, application context gives engineers, architects, and executives a shared way to decide what deserves action first. What context most often changes your remediation priority? To view or add a comment, sign in 376,545 followers More from this author Lance Spitzner on What Comes After Behavior Change? SANS Institute 3d Lance Spitzner on What Comes After Behavior Change? Lance Spitzner on Elevating Human Risk to a Strategic Priority SANS Institute 7mo Lance Spitzner on Elevating Human Risk to a Strategic Priority Explore content categories Soft Skills & Emotional Intelligence Project Management User Experience Sign in to view more content Create your free account or sign in to continue your search New to LinkedIn? Join now By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement , Privacy Policy , and Cookie Policy . Never miss a beat on the app Don’t have the app? Get it in the Microsoft Store.
📥 下载地址(文章结尾)
装机神器安装一切系统。