...
首页> 外文期刊>Journal in computer virology >On the role of the Facilitator in information security risk assessment
【24h】

On the role of the Facilitator in information security risk assessment

机译:关于促进者在信息安全风险评估中的作用

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In organisations where information security has historically been a part of management and for which the risk assessment methodologies have been designed there are established methods for communicating risk. This is the case for example in the banking and military sectors. However in organisations where information security is not embedded into management thinking and where the relationship between information security and the business is less clear-cut, communicating the risks to the business is less straightforward. In such circumstances it has been observed during field research that information security risk assessments frequently output findings to which the business cannot relate and the process is consequently often viewed as a “tick box” exercise, as opposed to one that provides real value to the business. In such a situation the information security risk assessment is divorced from the business process and not embedded into the organisation’s processes or thinking. The research for this paper was undertaken in order to identify what needs to be done in order to ensure that businesses of this type find the risk assessment process valuable in practice.
机译:在信息安全历来是管理的一部分并且已经为其设计了风险评估方法的组织中,已经建立了用于传达风险的方法。例如在银行和军事部门就是这种情况。但是,在没有将信息安全性嵌入管理思想中并且信息安全性与业务之间的关系不那么清晰的组织中,将风险传达给业务的方式就不那么直接了。在这种情况下,在实地研究中发现,信息安全风险评估经常会输出与业务无关的发现,因此该过程通​​常被视为“勾选”练习,而不是为业务提供真正价值的练习。 。在这种情况下,信息安全风险评估会脱离业务流程,而不会嵌入组织的流程或思想中。进行本文的研究是为了确定需要做什么,以确保此类企业发现风险评估过程在实践中有价值。

著录项

  • 来源
    《Journal in computer virology》 |2007年第2期|143-148|共6页
  • 作者单位

    1.Department of Computer Science King’s College London Strand London WC2R 2LS UK;

    1.Department of Computer Science King’s College London Strand London WC2R 2LS UK;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号