【24h】

ACHIEVING A RISK INFORMED SECURITY POSTURE

机译:实现风险告知的安全状态

获取原文

摘要

The U. S. Department of Energy (DOE) has long sought to "right size" its security posture by establishing a formal method to identify and evaluate the risks associated with malevolent actions directed toward the national security assets. Identifying and prioritizing risks allows managers to apply risk management techniques to control and monitor overall operational risks, including security risks. This paper will briefly summarize the evolution of the Department's approach to risk assessment, beginning with the initial availability of the IBM Personal Computer in 1981 to the present computational capacity available to security professionals. As computing capacity has increased, so has the complexity of the analyses that can be performed. This paper will also discuss whether these increasing complex analyses and the associated expectations of DOE regulators and managers have actually enhanced management's understanding of the risk environment and advanced its ability to effectively manage risk.
机译:美国能源部(DOE)长期以来一直在寻求通过建立一种正式方法来“确定大小”其安全态势,以识别和评估与针对国家安全资产的恶意行动相关的风险。识别风险并确定优先级后,管理人员可以应用风险管理技术来控制和监视包括安全性风险在内的整体操作风险。本文将从1981年IBM个人计算机的首次可用性到安全专业人员现在可以使用的计算能力开始,简要概述该部门进行风险评估的方法的发展。随着计算能力的提高,可以执行的分析的复杂性也随之提高。本文还将讨论这些不断增加的复杂分析以及DOE监管者和管理者的相关期望是否实际上增强了管理层对风险环境的理解并提高了其有效管理风险的能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号