摘要
本文主要讨论了等级保护测评过程中风险分析与风险评估方法的运用,给出了如何将测评发现与风险评估过程相结合的方法,尤其是如何从测评发现中识别脆弱性。
This paper focuses on the application of risk analysis and risk assessment methods in testing and evaluation process for classified protection of cybersecurity,and discusses how to combine assessment discovery with risk assessment process,especially with vulnerability identification.
作者
谢宗晓
甄杰
董坤祥
Xie Zongxiao;Zhen Jie;Dong Kunxiang(China Financial Certification Authority;School of Management Science and Engineering,Chongqing Technology and Business University;School of Management Science and Engineering,Shandong University of Finance and Economics)
出处
《中国质量与标准导报》
2020年第4期21-24,共4页
China Quality and Standards Review
关键词
等级保护
网络安全
风险分析
风险评估
classified protection,cybersecurity,risk analysis,risk assessment