首页> 外文会议>Model Driven Engineering Languages and Systems; Lecture Notes in Computer Science; 4199 >A Graphical Approach to Risk Identification, Motivated by Empirical Investigations
【24h】

A Graphical Approach to Risk Identification, Motivated by Empirical Investigations

机译:基于经验调查的图形化风险识别方法

获取原文
获取原文并翻译 | 示例

摘要

We propose a graphical approach to identify, explain and document security threats and risk scenarios. Security risk analysis can be time consuming and expensive, hence, it is of great importance that involved parties quickly understand the risk picture. Risk analysis methods often make use of brainstorming sessions to identify risks, threats and vulnerabilities. These sessions involve system users, developers and decision makers. They typically often have completely different backgrounds and view the system from different perspectives. To facilitate communication and understanding among them, we have developed a graphical approach to document and explain the overall security risk picture. The development of the language and the guidelines for its use have been based on a combination of empirical investigations and experiences gathered from utilizing the approach in large scale industrial field trials. The investigations involved both professionals and students, and each field trial was in the order of 250 person hours.
机译:我们提出一种图形化方法来识别,解释和记录安全威胁和风险方案。安全风险分析可能既耗时又昂贵,因此,让相关方快速了解风险状况非常重要。风险分析方法通常利用集思广益会议来识别风险,威胁和漏洞。这些会议涉及系统用户,开发人员和决策者。他们通常通常具有完全不同的背景,并从不同的角度看待系统。为了促进他们之间的沟通和理解,我们开发了一种图形方法来记录和解释总体安全风险状况。语言的开发和使用指南是基于实证研究和从大规模工业现场试验中使用该方法收集的经验的结合。调查涉及专业人士和学生,每次现场试验大约需要250人时。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号