首页> 外文会议>IEEE Annual International Carnahan Conference on Security Technology >EVALUATION OF INFORMATION SECURITY RELATED RISKS OF AN ORGANIZATION-THE APPLICATION OF THE MULTI-CRITERIA DECISION-MAKING METHOD
【24h】

EVALUATION OF INFORMATION SECURITY RELATED RISKS OF AN ORGANIZATION-THE APPLICATION OF THE MULTI-CRITERIA DECISION-MAKING METHOD

机译:评估信息安全相关风险的组织 - 应用多标准决策方法

获取原文

摘要

In the wake of the fast popularization of information and the rise of electronic commerce, information security is gaining much attention. How to perform the evaluation of the value of assets, how to perform the analysis of the risks associated with assets, and how to protect information assets from sabotage, theft and tamper are important topics in the study of the management of information security. This research addresses the aspects of confidentiality, integrity and availability of information and applies the Analytic Hierarchy Process (AHP) to consolidate expert's opinions on information risks, in order to construct an integrated framework for risk analysis. The BS7799 standard and the risk level matrix(RLM) are used accordingly to evaluate the effectiveness of and to categorize the risk management measures and to create a complete model for the assessment of information assets related risks. Finally, the research results are verified by a case study. The results can be used by organizations as references for information security planning and management process improvements.
机译:在信息的快速普及和电子商务的兴起之后,信息安全性越来越大。如何执行资产价值的评估,如何执行与资产相关的风险分析,以及如何保护信息资产免受破坏,盗窃和篡改是关于信息安全管理研究的重要主题。本研究涉及信息的机密性,完整性和可用性方面,并应用分析层次处理(AHP),以巩固专家对信息风险的看法,以构建风险分析的综合框架。 BS7799标准和风险级矩阵(RLM)相应地使用,以评估风险管理措施的有效性,并为信息资产评估相关风险的完整模型。最后,通过案例研究验证了研究结果。结果可以由组织作为信息安全规划和管理流程改进的参考。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号