首页> 外文会议>20th International System Safety Conference, Aug 5-9, 2002, Denver, CO >The Leveraging of Safety and Information Security Engineering Principles: Establishing an Effective Level of Integrated Risk Management
【24h】

The Leveraging of Safety and Information Security Engineering Principles: Establishing an Effective Level of Integrated Risk Management

机译:充分利用安全和信息安全工程原理:建立有效的集成风险管理水平

获取原文
获取原文并翻译 | 示例

摘要

In the overall goal of building safe, secure, and efficient systems, aligning safety and information security principles within a system engineering methodology can aid in achieving an effective system solution. The foundation of which lies in managing safety and information security risk associated with the system throughout its lifecycle. Integrated safety and information security risk management revolves around four primary activities. Hazard identification aids in capturing system hazards and vulnerabilities. The next activity involves assessing the hazard effect or impact and prioritizing risk into appropriate levels to be managed. Prioritizing risk aids in evaluating and balancing candidate system safety and information security requirements. Finally, balanced requirements are incorporated into the system specification for system design and implementation. Integrating system safety and information security into the system development lifecycle is advantageous for the following reasons. First, system development goals can more effectively be achieved when system safety and information security issues are resolved and risk mitigation requirements are implemented during the design. Second, it is less expensive and obtrusive to integrate risk mitigation requirements in the design than to force them at the end. By leveraging the engineering principles, the foundation of managing safety and security risk can effectively pursue adequate levels of safety and security.
机译:在构建安全,可靠和高效的系统的总体目标中,在系统工程方法论中调整安全性和信息安全性原则可以帮助实现有效的系统解决方案。其基础在于管理与系统整个生命周期相关的安全和信息安全风险。集成的安全和信息安全风险管理围绕四个主要活动。危害识别有助于捕获系统危害和漏洞。下一个活动涉及评估危害影响或影响,并将风险划分为适当级别进行管理。优先考虑风险有助于评估和平衡候选系统的安全性和信息安全性要求。最后,将平衡的要求合并到系统规范中,以进行系统设计和实施。由于以下原因,将系统安全性和信息安全性集成到系统开发生命周期中是有利的。首先,解决系统安全和信息安全问题并在设计过程中实施降低风险的要求,可以更有效地实现系统开发目标。其次,将风险缓解要求集成到设计中要比强制最终降低成本和麻烦。通过利用工程原理,管理安全和保障风险的基础可以有效地追求足够水平的安全与保障。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号