首页> 外文会议>International conference on security management >Decision Support for Assessment of IT-Security Risks
【24h】

Decision Support for Assessment of IT-Security Risks

机译:评估IT安全风险的决策支持

获取原文

摘要

IT-security risks can have a great impact on organizations and can cause high financial damage. To address security issues and avoid problems, knowledge about risks is vital. Therefore, a risk assessment process, which addresses security of IT-systems, is essential. However, risk assessment methods based on qualitative or quantitative approaches involve some difficulties and limitations. Therefore, in this research, we propose a risk assessment method based on semi-quantitative approach. The method provides decision support for security experts during evaluation of IT-security risks and enables assessment of threats both at a detailed level and as a whole. Imprecise information is captured from expert judgment and expressed numerically in interval form. The method is applied to a scenario in order to demonstrate its usage. We utilize a decision tool to present the outcomes. Moreover, sensitivity analysis is performed to point out most critical values.
机译:IT安全风险可能会对组织产生重大影响,并可能造成严重的财务损失。为了解决安全问题并避免出现问题,有关风险的知识至关重要。因此,解决IT系统安全性的风险评估过程至关重要。但是,基于定性或定量方法的风险评估方法存在一些困难和局限性。因此,在本研究中,我们提出了一种基于半定量方法的风险评估方法。该方法在评估IT安全风险期间为安全专家提供决策支持,并可以在详细级别和整体上评估威胁。不精确的信息是从专家判断中捕获的,并以间隔形式用数字表示。该方法应用于场景以演示其用法。我们使用决策工具来呈现结果。此外,执行灵敏度分析以指出最关键的值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号