期刊文献+

基于GB/T 20984的信息安全风险评估模型与综合评价方法 被引量:1

The information security risk evaluation model and method based on GB/T 20984
原文传递
导出
摘要 在GB/T 20984的基础上建立了信息安全风险评估的数学模型;通过定义"风险熵",以定量描述各风险域及系统整体风险状态的不确定性程度,揭示信息安全风险随系统复杂程度而递增的规律;对信息安全风险评估和系统风险的整体评价进行了理论归纳. Based on the standard, GB/T20984- information security technology-risk assessment specification for information security, a math model was built to evaluate information security risk. The definition of risk entropy was given to quantify the uncertainty of the risk state in every risk domain and the whole system, and the law, the system more complex, the more information security risks, was discovered. The risk evaluation of information security and system risk synthetical assessment method was also theoretically concluded.
出处 《四川大学学报(自然科学版)》 CAS CSCD 北大核心 2010年第3期469-472,共4页 Journal of Sichuan University(Natural Science Edition)
关键词 风险评估 风险概率 风险熵 评估规范 risk evaluation, risk probability, risk entropy, evaluation standard
  • 相关文献

参考文献4

二级参考文献5

  • 1[3]Bedford T,Cooke R.Probabilistic Risk Analysis[M].北京:世界图书出版公司,2003.
  • 2[4]Anand D K,Zmood R B.Introduction to Control Systems[M].北京:世界图书出版公司,2003.
  • 3Government of Canada. Canadian Trusted Computer Product Evaluation Criteria, Version 3.0[ M]. Canada: Canadian System Security Center, 1993.
  • 4William Stallings. Intemet Security Handbook[M]. USA:IDG Books Worldwide, Inc,1995.
  • 5Lopez Crespo. Evaluation and Certification Activities in Spain[M]. USA: First International Common Criteria Conference,2000.

共引文献25

同被引文献5

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部