首页> 外文会议>International systems safety conference >The Leveraging of Safety and Information Security Engineering Principles: Establishing an Effective Level of Integrated Risk Management
【24h】

The Leveraging of Safety and Information Security Engineering Principles: Establishing an Effective Level of Integrated Risk Management

机译:利用安全和信息安全工程原则:建立有效的综合风险管理水平

获取原文

摘要

In the overall goal of building safe, secure, and efficient systems, aligning safety and information security principles within a system engineering methodology can aid in achieving an effective system solution. The foundation of which lies in managing safety and information security risk associated with the system throughout its lifecycle. Integrated safety and information security risk management revolves around four primary activities. Hazard identification aids in capturing system hazards and vulnerabilities. The next activity involves assessing the hazard effect or impact and prioritizing risk into appropriate levels to be managed. Prioritizing risk aids in evaluating and balancing candidate system safety and information security requirements. Finally, balanced requirements are incorporated into the system specification for system design and implementation. Integrating system safety and information security into the system development lifecycle is advantageous for the following reasons. First, system development goals can more effectively be achieved when system safety and information security issues are resolved and risk mitigation requirements are implemented during the design. Second, it is less expensive and obtrusive to integrate risk mitigation requirements in the design than to force them at the end. By leveraging the engineering principles, the foundation of managing safety and security risk can effectively pursue adequate levels of safety and security.
机译:在构建安全,安全和高效的系统的整体目标中,在系统工程方法中对准安全和信息安全原理可以帮助实现有效的系统解决方案。其中的基础是管理与系统相关联的安全和信息安全风险的基础。综合安全和信息安全风险管理围绕四个主要活动。危险识别辅助捕获系统危害和漏洞。下一个活动涉及评估危害效果或影响以及对待管理的适当级别的风险。在评估和平衡候选系统安全和信息安全要求时,优先考虑风险辅助。最后,将均衡要求纳入系统设计和实现的系统规范中。由于以下原因,将系统安全和信息安全集成到系统开发生命周期中是有利的。首先,当系统安全和信息安全问题得到解决并且在设计期间实施了风险缓解要求时,可以更有效地实现系统开发目标。其次,它不太昂贵且令人痛苦地整合设计中的风险缓解要求而不是在最后施力。通过利用工程原则,管理安全和安全风险的基础可以有效地追求充分的安全和安全水平。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号