首页> 外文会议>2014 10th International Conference on Reliability, Maintainability and Safety >Research on the calculation method of information security risk assessment considering human reliability
【24h】

Research on the calculation method of information security risk assessment considering human reliability

机译:考虑人员可靠性的信息安全风险评估计算方法研究

获取原文
获取原文并翻译 | 示例

摘要

Information security risk assessment is the premise and basis for ensuring the security of information systems. Current research on risk assessment focuses on the calculation methods and assessment models of the risk value. Also, lots of automatic assessment tools have been applied to risk assessment. However, these methods didn't take human errors in risk assessment work into consideration, thus couldn't solve the problem brought by the influence of human errors on final assessment results. As a result, this paper introduces the Technique for Human Error Rate Prediction (THERP) which is a mature technique in human reliability analysis into the process of information security risk assessment. Combined with current analysis techniques of human errors in computer science and aiming at the calculation process of the risk value of important assets in information security risk assessment, research on the calculation method of risk value considering human reliability is carried out in this paper. The calculation method of human error rates in the entire process of risk value calculation is proposed. An example is provided to verify the method proposed in this paper.
机译:信息安全风险评估是确保信息系统安全的前提和基础。当前的风险评估研究集中于风险价值的计算方法和评估模型。此外,许多自动评估工具已应用于风险评估。但是,这些方法没有考虑风险评估工作中的人为错误,因此无法解决人为错误对最终评估结果的影响所带来的问题。因此,本文将人为错误率预测技术(THERP)引入到信息安全风险评估过程中,该技术是人的可靠性分析中的一项成熟技术。结合当前计算机科学中人为错误的分析技术,针对信息安全风险评估中重要资产风险价值的计算过程,对考虑人的可靠性的风险价值计算方法进行了研究。提出了风险价值计算全过程中人为错误率的计算方法。通过实例验证了本文提出的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号