首页> 外文会议>2016 IEEE International Conference on Knowledge Engineering and Applications >An expert system for risk assessment of information system security based on ISO 27002
【24h】

An expert system for risk assessment of information system security based on ISO 27002

机译:基于ISO 27002的信息系统安全风险评估专家系统

获取原文
获取原文并翻译 | 示例

摘要

Information system security in a company is an important element that every company should pay more attention due to the attacks against the security of the data that may not be inevitable. Probably every company knows how to protect their data even though this paper proposes something new which is more efficient. One of the ways that can be used to determine the security status of the company is by doing a risk assessment. This study proposes an expert system to determine the position or the level of the security system of a company by doing a risk assessment. The standard of risk assessment is based on the ISO 27002. Forward chaining method is used for the determination of rules and scoring in this expert system. The conclusion of this study is that the integration between the risk assessment and expert system helps in determining the position of a company-level security and also determining whether the company needs to do an audit of their information systems security or not.
机译:公司中的信息系统安全性是一个重要因素,由于可能不可避免地遭受对数据安全性的攻击,因此每个公司都应给予更多关注。也许每个公司都知道如何保护其数据,即使本文提出了一些更有效的新方法。确定公司安全状态的一种方法是进行风险评估。这项研究提出了一个专家系统,可以通过进行风险评估来确定公司安全系统的位置或级别。风险评估的标准基于ISO27002。在此专家系统中,正向链接法用于确定规则和评分。这项研究的结论是,风险评估和专家系统之间的集成有助于确定公司级安全性的位置,还可以确定公司是否需要对其信息系统安全性进行审核。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号