期刊文献+

信息系统安全风险评估若干问题的探讨

Discussion on Some Operational Problems of Information System Security Risk Assessment
下载PDF
导出
摘要 信息安全风险评估规范以及相关指南的发布指导了评估工作的开展,但在实际评估过程中存在一些操作性不强或容易混淆的评估方法。本文首先回顾了目前的信息安全风险评估方法,分析了其存在的不足;然后提出了一套新的信息系统的资产分类、威胁分类和系统总体风险评估方法,并概述了建议方法的实用效果。 The publications of risk assessment specification for information security and other related operation guides greatly help people to carry out risk assessment, but there are many assessment methods which are not easy to operate or which may cause confusions. Firstly, the paper describes the current information system security risk assessment methods, and it gives their shortcomings. Then the new risk assessment method is suggested, which covers asset classification, threat classification and risk assessment method of the whole information system. In the end, the paper summarizes the practical effect of the suggested method.
机构地区 山东省计算中心
出处 《信息技术与信息化》 2008年第6期83-85,共3页 Information Technology and Informatization
关键词 信息安全 风险评估 资产 威胁 分类 Information security Risk assessment Asset Threat Classification
  • 相关文献

参考文献4

  • 1范红,吴亚非,李景春等.GB/T 20984-2007信息安全技术信息安全风险评估规范[S].北京:中国标准出版社,2007.
  • 2ISO/IEC 17799:2005 (E) Information technology - Security techniques - Codes of practice for information security management[ S]. ISO, 2005.
  • 3赵冬梅,马建峰,王跃生.信息系统的模糊风险评估模型[J].通信学报,2007,28(4):51-56. 被引量:63
  • 4Christopher Alberts, Audrey Dorofee. Managing Information Security Risks : The OCTAVE Approach [ M ]. 吴唏,译.北京:清华大学出版社,2003.

二级参考文献16

共引文献63

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部