【24h】

ACHIEVING A RISK INFORMED SECURITY POSTURE

机译:实现风险了解安全姿势

获取原文

摘要

The U. S. Department of Energy (DOE) has long sought to "right size" its security posture by establishing a formal method to identify and evaluate the risks associated with malevolent actions directed toward the national security assets. Identifying and prioritizing risks allows managers to apply risk management techniques to control and monitor overall operational risks, including security risks. This paper will briefly summarize the evolution of the Department's approach to risk assessment, beginning with the initial availability of the IBM Personal Computer in 1981 to the present computational capacity available to security professionals. As computing capacity has increased, so has the complexity of the analyses that can be performed. This paper will also discuss whether these increasing complex analyses and the associated expectations of DOE regulators and managers have actually enhanced management's understanding of the risk environment and advanced its ability to effectively manage risk.
机译:美国能源部(DOE)通过建立正式的方法来旨在确定和评估针对国家安全资产的恶性行动相关的风险,长期以来其安全姿势。确定和优先级风险允许管理人员应用风险管理技术来控制和监控整体运营风险,包括安全风险。本文将简要概述该部门的风险评估方法的演变,从1981年IBM个人计算机的初步可用性开始到安全专业人员的目前的计算能力。随着计算能力增加,所以可以执行分析的复杂性。本文还将讨论这些增加的复杂分析以及对DOE监管机构和管理人员的相关预期实际上还提高了管理层对风险环境的理解,并提高了其有效管理风险的能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号