摘要
安全风险评估是信息系统安全工程的重要组成部分,是建立信息系统安全保障体系的基础和前提。文中对军工行业信息系统安全风险评估的主要内容、关键环节和评估准则进行了阐述,并结合实际风险评估工作给出了风险评估的基本方法和经验性策略,最后对军工行业信息系统的典型安全威胁和系统脆弱性进行了分析和归纳。
Risk assessment is very important for security assurance of information systems in war industry. The main contents, key technologies and principles of security risk assessment are described in this paper. Then, the basic methods and some practical advice on risk assessment and threat analysis for different kinds of information system are presented. Finally, the typical security threats and vulnerabilities of information systems in war industry are analyzed and summarized.
出处
《信息安全与通信保密》
2010年第1期64-66,69,共4页
Information Security and Communications Privacy
关键词
信息系统
风险评估
安全威胁
系统脆弱性
information system
risk assessment
security threat
system vulnerability