首页> 外文OA文献 >A framework for estimating information security risk assessment method completeness: Core Unified Risk Framework
【2h】

A framework for estimating information security risk assessment method completeness: Core Unified Risk Framework

机译:估算信息安全风险评估方法完整性的框架:核心统一风险框架

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In general, an information security risk assessment (ISRA) method produces risk estimates, where risk is the product of the probability of occurrence of an event and the associated consequences for the given organization. ISRA practices vary among industries and disciplines, resulting in various approaches and methods for risk assessments. There exist several methods for comparing ISRA methods, but these are scoped to compare the content of the methods to a predefined set of criteria, rather than process tasks to be carried out and the issues the method is designed to address. It is the lack of an all-inclusive and comprehensive comparison that motivates this work. This paper proposes the Core Unified Risk Framework (CURF) as an all-inclusive approach to compare different methods, all-inclusive since we grew CURF organically by adding new issues and tasks from each reviewed method. If a task or issue was present in surveyed ISRA method, but not in CURF, it was appended to the model, thus obtaining a measure of completeness for the studied methods. The scope of this work is primarily functional approaches risk assessment procedures, which are the formal ISRA methods that focus on assessments of assets, threats, vulnerabilities, and protections, often with measures of probability and consequence. The proposed approach allowed for a detailed qualitative comparison of processes and activities in each method and provided a measure of completeness. This study does not address aspects beyond risk identification, estimation, and evaluation; considering the total of all three activities, we found the “ISO/IEC 27005 Information Security Risk Management” to be the most complete approach at present. For risk estimation only, we found the Factor Analysis of Information Risk and ISO/IEC 27005:2011 as the most complete frameworks. In addition, this study discovers and analyzes several gaps in the surveyed methods.
机译:通常,信息安全风险评估(ISRA)方法会产生风险估计,其中风险是事件发生的概率和给定组织的相关后果的乘积。 ISRA的实践因行业和学科而异,因此产生了各种风险评估方法。存在几种用于比较ISRA方法的方法,但是这些方法的范围是将方法的内容与一组预定义的标准进行比较,而不是将要执行的处理任务以及该方法要解决的问题。缺乏全面的,全面的比较推动了这项工作。本文提出了核心统一风险框架(CURF),将其作为一种包罗万象的方法来比较不同的方法,因为我们通过在每种已审查方法中添加新的问题和任务来有机地发展CURF,从而实现了包容性。如果在调查的ISRA方法中存在任务或问题,而在CURF中不存在,则将其附加到模型中,从而获得所研究方法的完整性度量。这项工作的范围主要是功能方法风险评估程序,这是ISRA的正式方法,该方法着重于资产,威胁,漏洞和保护的评估,通常采用概率和后果的度量。提议的方法允许对每种方法中的过程和活动进行详细的定性比较,并提供完整性的度量。这项研究没有涉及风险识别,估计和评估之外的其他方面;考虑到这三项活动的总和,我们发现“ ISO / IEC 27005信息安全风险管理”是目前最完整的方法。仅就风险估计而言,我们发现信息风险因素分析和ISO / IEC 27005:2011是最完整的框架。此外,本研究发现并分析了所调查方法中的一些差距。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号