期刊文献+

基于业务过程建模的信息安全风险评估 被引量:1

Information Asset Identification and Assessment based on Business Process Modeling
下载PDF
导出
摘要 信息安全风险评估中,一般根据资产的表现形式给出分类的资产列表并孤立地为资产赋值,没有考虑到资产对业务的支持和资产之间的关联性。以业务过程建模方法 IDEF0(Integration DEFinition Method 0)为基础,建立层次化的业务过程功能模型,并识别与每个过程功能实现有关的输入、机制、控制三类支持性资产,从而得到以业务过程为中心的层次化的资产关联图。图中的业务过程构成了一个典型的具有内部依赖的递阶层次结构,利用网络分析法可以评估业务过程针对系统总目标的重要性排序,根据所支持的业务过程的重要性及其数量评估支持性资产的重要性。该方法实现了层次化的资产关联、识别与评估,电子购物网站的应用实例证实了此方法的可行性。 In the information security risk assessment,it is often to give a list of assets that are classified based on the manifestations of assets and evaluate every asset isolated. This study presents a hierarchical functional model of business process based on IDEF0 and identifies three kinds of supporting assets-input, machine and control and finally a business process-centric hierarchical correlation graph of assets is obtained. In the graph,the business processes constitute a typical hierarchy with internal dependences,and thus,ANP can be used to assess the priorities of business processes with respect to objective of the system and the other supporting assets are evaluated according to importance and number of business processes that they support. The method achieves hi-erarchical association,identification and assessment of assets and its application to online shopping website shows it is feasi-ble.
作者 范士喜
出处 《北京印刷学院学报》 2015年第4期39-44,共6页 Journal of Beijing Institute of Graphic Communication
基金 北京市自然科学基金(4142016)
关键词 信息安全 风险评估 资产识别 IDEF0 网络分析法 information security risk assessment asset iden-tification
  • 相关文献

参考文献8

  • 1ISO/IEC 27005 : 2011. Information technology-Security techniques-Information security risk management ( second edition) [ S ]. Geneva Switzerland, ISO/IEC, 2011:7.
  • 2GB-T20984-2007信息安全技术信息安全风险评估规范[S].北京:国家质量监督检验疫总局,2007:2.
  • 3Stefan Fenz, Andreas Ekelhart, Thomas Neubauer. Business Process-Based Resource Importance Determination [ EB/OL ]. (2009-05-01) [ 2015-07-10 ]. http://publik, tuwien, ac. at/ files/PubDat_185911, pdf.
  • 4Suh B, Han I. The IS Risk Analysis Based on a Business Model [ J]. Information & Management, 2003 (41) : 149-158.
  • 5Zhang Hao, Zhang Jianhua, Liu Nian, et al. Function-Oriented Information Assets Identification on Substation Automation Systems [ EB/OL ]. ( 2009-03-31 ) [ 2015-07-10 ] http:// ieeexplore, ieee. org/xpl/login, jsp? tp = &arnumber = 4918391&url = http% 3A% 2F% 2Fieeexplore. ieee. org% 2Fxpls% 2 Fabs_all. jsp% 3 Farnumber% 3 D4918391.
  • 6唐任仲,周广民,汤洪涛.过程管理建模技术分析[J].浙江大学学报(工学版),2002,36(4):385-388. 被引量:25
  • 7王莲芬.网络分析法(ANP)的理论与算法[J].系统工程理论与实践,2001,21(3):44-50. 被引量:486
  • 8SAATY T L. Decision Making with Dependence and Feedback [ M ]. Pittsburgh: RWS Publication, 1996 : 1-386.

二级参考文献7

共引文献509

同被引文献12

引证文献1

二级引证文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部