首页> 外国专利> Technology Risk Assessment, Forecasting, and Prioritization

Technology Risk Assessment, Forecasting, and Prioritization

机译:技术风险评估,预测和优先级

摘要

A computer system assesses the overall risk for different technologies for an organization. Technologies may be evaluated by obtaining severity levels and environmental risk scores for the vulnerabilities associated with the technologies. Each severity level measures a possible risk level of a corresponding vulnerability, while each environmental risk score is based on the organization's environment. Technology risk scores are then determined from the severity levels and the environmental risk scores. Each technology may then be categorized from a statistical distribution of the technology risk scores. An indexed risk score for each technology may also be determined based on time trending variables. Inputs may be a number of vulnerabilities, blended advisory/severity scores, and a standard deviation of the blended advisory/severity scores, and the results then provide behavior forecasting of the technologies. Further evaluation of the technologies may be performed to determine a risk versus reward model for the different technologies.
机译:计算机系统评估组织使用不同技术的总体风险。可以通过获取与技术相关的漏洞的严重性级别和环境风险评分来评估技术。每个严重性级别衡量相应漏洞的可能风险级别,而每个环境风险评分均基于组织的环境。然后根据严重性级别和环境风险分数确定技术风险分数。然后可以根据技术风险评分的统计分布对每种技术进行分类。还可以基于时间趋势变量来确定每种技术的索引风险评分。输入可能是许多漏洞,咨询/严重性混合分数和咨询/严重性混合分数的标准偏差,然后结果可以提供技术的行为预测。可以对技术进行进一步评估,以确定不同技术的风险与回报模型。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号