【24h】

Risk Management for IT Security: When Theory Meets Practice

机译:IT安全风险管理:理论与实践相结合

获取原文
获取原文并翻译 | 示例

摘要

A Layer-Based Risk Tool (LBRT) for IT security management in a corporate environment is presented and discussed. The Risk-Rank algorithm is modified for implementation in this tool by taking practical considerations into account. The focus is shifted to a security requirement-based approach during actual assessment of operational risk in the organization and absolute risk values are computed instead of relative risk probabilities. In addition, a risk mitigation algorithm is proposed to find the optimum set of measures under certain budget constraints. A dynamic programming formulation is presented and a shortest path solution is obtained based on Dijkstra's algorithm. The risk assessment and mitigation algorithms are illustrated and evaluated with numerical examples.
机译:提出并讨论了用于企业环境中IT安全管理的基于层的风险工具(LBRT)。考虑到实际情况,对Risk-Rank算法进行了修改,以便在此工具中实施。在组织中实际评估操作风险期间,重点已转移到基于安全需求的方法,并计算绝对风险值而不是相对风险概率。此外,提出了一种风险缓解算法,以在某些预算约束下找到最佳的措施集。提出了一种动态规划公式,并基于Dijkstra算法获得了最短路径求解。举例说明并评估了风险评估和缓解算法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号