2ISO/IEC. 13335 - 1 - 2004, Information technology - Secmity techniques-Management of intbrmation and communications technology security-Part 1 : Coneepls and models for informa- tion and communications technology security management[ S]. Switzerland:lSO/lEC, 2004 ( 2004. 11.15 ) : [ 2015.2.10 ] ht- tps ://www. iso. org/obp/ui/#iso : std : 39066 : en.
3National Institute of Standards and Technology. Special Publi- cation 800-30800-30 Revision 1:2012- Guide for Conduc- ting Risk Assessments [ S ]. United State : National Institute of Standards and Technology ,2012( 2012.9 ) [ 2015.2.10 ]. http://esrc, nist. gov/publications/nistpubs/800 - 30 - revl/ sp800_30_ rl .pdf.