期刊文献+

风险评估服务能力成熟度模型研究 被引量:1

Risk Assessment Service Capability Maturity Model Research
下载PDF
导出
摘要 信息安全风险评估服务是我国信息安全保障工作的重要环节之一,信息安全风险评估技术手段一直为行业内所推崇.目前,因多方面因素影响,信息安全风险评估服务能力的水平在地区、行业间等呈现参差不齐的现象.结合SSE-CMM理论及信息安全风险评估服务的最优实践,提出风险评估服务能力成熟度模型概念,即RAS-CMM.RAS-CMM围绕资源配置、技术过程、项目管理等能力因素对风险评估服务能力等级提出理论评价框架. Information security risk assessment service is one of the important links of information security assurance in China. The technology of information security risk assessment has been praised highly by the industry. At present, due to the influence of various factors, the level of information security risk assessment service capacity varies among regions and industries. Based on the SSE CMM theory and the optimal practices of information security risk assessment services, this paper proposes the concept of risk assessment service capability maturity model, namely RAS-CMM. RA&CMM proposes a theoretical evaluation framework for risk assessment service capability level based on resource allocation, technical process and proiect management.
作者 孙明亮 位华 王琰 Sun Mingliang;Wei Hua;and Wang Yan(China In formtion Technology Security Evaluation Center,Beijing 100085;School of Cyberspace Security,Beijing University of Posts and Telecommunications,Beijing 100876)
出处 《信息安全研究》 2018年第10期889-897,共9页 Journal of Information Security Research
关键词 信息安全 风险评估 服务 过程域 基本实施 公共特征 通用实施 能力成熟度模型 information security risk assessment service process areas base practices commonfunction generic practices capability maturity
  • 相关文献

同被引文献5

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部