期刊文献+

油田企业信息安全风险评估模型研究 被引量:2

Infosec Risk Assessment Model of Oilfield Enterprise
下载PDF
导出
摘要 在分析总结现有国内外风险评估研究成果基础上,通过对某油田企业的风险评估需求进行分析,提出适应该企业的一种改进的风险评估模型及计算方法。该模型引入了不可接受安全事件,从而减少了计算工作量;并将脆弱性要素赋值细化为暴露程度及严重程度两个权重,将现有安全措施细化为预防措施和恢复措施,从而使得调整因子和赋值更贴合实际,也提升了计算结果的准确性。 Based on summarizing and analyzing the research resuhs of existing risk assessment both at home and abroad, and through the analysis on risk assessment demand of certain oil enterprise, the paper presents an improved risk assessment model and calculation methods. The unacceptable security incidents is introduces into the model, thus to reduce the calculation workload. The vulnerability factor is refined for two weights of exposure levels and severity level, and the existing security measure refined for prevention measure and recovery measure, thus making the adjustment factor and the assignment stick more suitable to reality, and meanwhile, improving the accuracy of calculation results.
出处 《信息安全与通信保密》 2015年第9期103-108,共6页 Information Security and Communications Privacy
关键词 风险评估 不可接受事件 威胁 脆弱性 资产 risk assessment unacceptable incident threat vulnerability asset
  • 相关文献

参考文献3

  • 1ISO/IEC. 13335 - 1 - 2004, Information technology - Secmity techniques-Management of intbrmation and communications technology security-Part 1 : Coneepls and models for informa- tion and communications technology security management[ S]. Switzerland:lSO/lEC, 2004 ( 2004. 11.15 ) : [ 2015.2.10 ] ht- tps ://www. iso. org/obp/ui/#iso : std : 39066 : en.
  • 2National Institute of Standards and Technology. Special Publi- cation 800-30800-30 Revision 1:2012- Guide for Conduc- ting Risk Assessments [ S ]. United State : National Institute of Standards and Technology ,2012( 2012.9 ) [ 2015.2.10 ]. http://esrc, nist. gov/publications/nistpubs/800 - 30 - revl/ sp800_30_ rl .pdf.
  • 3全国信息安全标准化技术委员会.GB/T20984-2007信息安全技术信息安全风险评估规范[S].北京:中国标准出版社,2007.

共引文献4

同被引文献7

引证文献2

二级引证文献6

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部