For the purpose of verifying the validity of network security policy effectively
an assessment model of network security policy based on security capability is proposed.Based on the establishment of security domain and security policy
the relationship of defense means
application targets
and information security attribute characteristics is analyzed
the protection factor and sensitivity factor are established
and then the value of security policy safety factor is obtained in order to assess the capability of the security policy capability.The result shows that the model can effectively reflect the protection ability of security policy and provide a new solution for assessing security polices.