首页> 外文会议>IFIP TC-11 WG 11.1 WG 11.5 Joint Working Conference >A HOLISTIC RISK ANALYSIS METHOD FOR IDENTIFYING INFORMATION SECURITY RISKS
【24h】

A HOLISTIC RISK ANALYSIS METHOD FOR IDENTIFYING INFORMATION SECURITY RISKS

机译:用于识别信息安全风险的整体风险分析方法

获取原文

摘要

Risk analysis is used during the planning of information security to identify security requirements, and is also often used to determine the economic feasibility of security safeguards. The traditional method of conducting a risk analysis is technology-driven and has several shortcomings. First, its focus on technology is at the detriment of considering people and processes as significant sources of security risk. Second, an analysis driven by technical assets can be overly time-consuming and costly. Third, the traditional risk analysis method employs calculations based largely on guesswork to estimate probability and financial loss of a security breach. Finally, an IT-centric approach to security risk analysis does not involve business users to the extent necessary to identify a comprehensive set of risks, or to promote security-awareness throughout an organization. This paper proposes an alternative, holistic method to conducting risk analysis. A holistic risk analysis, as defined in this paper, is one that attempts to identify a comprehensive set of risks by focusing equally on technology, information, people, and processes. The method is driven by critical business processes, which provides focus and relevance to the analysis. Key aspects of the method include a business-driven analysis, user participation in the analysis, architecture and data flow diagrams as a means to identify relevant IT assets, risk scenarios to capture procedural and security details, and qualitative estimation. The mixture of people and tools involved in the analysis is expected to result in a more comprehensive set of identified risks and a significant increase in security awareness throughout the organization.
机译:在信息安全计划期间使用风险分析来识别安全要求,并且通常用于确定安全保障的经济可行性。传统的进行风险分析方法是技术驱动的,有几个缺点。首先,其对技术的关注是损害考虑人员和流程,作为安全风险的重要来源。其次,由技术资产驱动的分析可能会过度耗时和昂贵。第三,传统风险分析方法主要采用基于猜测估计安全漏洞的概率和财务损失的计算。最后,以其为中心的安全风险分析方法不涉及企业用户,以确定全面的风险,或促进整个组织的安全意识。本文提出了一种进行风险分析的替代,整体方法。如本文所定义的全面风险分析是试图通过同样关注技术,信息,人员和流程来确定一套全面的风险。该方法由关键业务流程驱动,该过程提供了与分析的重点和相关性。该方法的关键方面包括业务驱动的分析,用户参与分析,架构和数据流程图作为识别相关IT资产,风险场景以捕获程序和安全细节以及定性估算的方法。预计分析中涉及的人和工具的混合物将导致更全面的识别风险和整个组织安全意识的显着增加。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号