首页> 外文会议>Computational Science - ICCS 2007 pt.3; Lecture Notes in Computer Science; 4489 >Risk Assessment Method Based on Business Process-Oriented Asset Evaluation for Information System Security
【24h】

Risk Assessment Method Based on Business Process-Oriented Asset Evaluation for Information System Security

机译:基于业务流程的资产评估的风险评估方法在信息系统安全中的应用

获取原文
获取原文并翻译 | 示例

摘要

We presented risk assessment methodology focused on business-process oriented asset evaluation and qualitative risk analysis method. The business process-oriented asset evaluation is to evaluate asset's value by the degree of asset contribution related to business process. Namely, asset's value is different according to the importance of department to which asset belongs, the contribution of asset's business, and security safeguard, etc. We proposed new asset's value evaluation applied to the weight of above factors. The weight is decided by evaluation matrix by Delphi team. We assess risk by qualitative method applied to the improved international standard method which is added the effectiveness of operating safeguard at information system. It reflects an assumption that they can reduce risk level when existent safeguards are established appropriately. Our model derives to practical risk assessment method than existent risk assessment method, and improves reliability of risk analysis.
机译:我们介绍了针对业务流程的资产评估和定性风险分析方法的风险评估方法。面向业务流程的资产评估是通过与业务流程相关的资产贡献程度来评估资产的价值。即,资产的价值根据资产所属部门的重要性,资产业务的贡献以及安全保障措施等的不同而有所不同。我们针对上述因素的权重,提出了新资产价值评估。权重由Delphi团队的评估矩阵决定。我们通过定性方法评估风险,将其应用于改进的国际标准方法,从而增加了信息系统中操作保障的有效性。它反映了这样一种假设,即在适当建立现有保障措施的情况下它们可以降低风险水平。我们的模型比现有的风险评估方法更适用于实际的风险评估方法,并提高了风险分析的可靠性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号