首页> 外国专利> Estimating and visualizing security risk in information technology systems

Estimating and visualizing security risk in information technology systems

机译:估计和可视化信息技术系统中的安全风险

摘要

Security risk for a single IT asset and/or a set of IT assets in a network such as an enterprise or corporate network may be estimated and represented in a visual form by categorizing risk into different discrete levels. The IT assets may include both computing devices and users. The risk categorization uses a security assessment of an IT asset that is generated to indicate the type of security problem encountered, the severity of the problem, and the fidelity of the assessment. The asset value of an IT asset to the enterprise is also assigned. Security risk is then categorized (and a numeric risk value provided) for each IT asset for different problem types by considering the IT asset value along with the severity and fidelity of the security assessment. The security risk for the enterprise is estimated using the numeric risk value and then displayed in visual form.
机译:通过将风险分为不同的离散级别,可以估算并以可视形式表示网络(例如企业或公司网络)中单个IT资产和/或一组IT资产的安全风险。 IT资产可能包括计算设备和用户。风险分类使用生成的IT资产的安全评估来指示遇到的安全问题的类型,问题的严重性以及评估的准确性。还分配了IT资产对企业的资产价值。然后,通过考虑IT资产价值以及安全评估的严重性和准确性,对每种IT资产针对不同问题类型的安全风险进行分类(并提供数字风险值)。使用数字风险值估算企业的安全风险,然后以可视形式显示。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号