首页 | 本学科首页   官方微博 | 高级检索  
     

ARCE风险处理计划测量模型的设计与实现
引用本文:刘琦,朱金娥,谢宗晓,孔金生.ARCE风险处理计划测量模型的设计与实现[J].计算机工程,2011,37(19):277-279.
作者姓名:刘琦  朱金娥  谢宗晓  孔金生
作者单位:1. 河南警察学院信息安全系,郑州,450002
2. 富士电机(杭州)软件有限公司,杭州,310012
3. 山东省信息安全测评中心,济南,250000
4. 郑州大学电气工程学院,郑州,450002
摘    要:提出用于定量测量风险处理计划有效性的ARCE模型,从理论上证明该模型的正确性.以组织信息安全资产的风险值和已实施控制措施为输入,通过中间变量矩阵得到风险处理计划有效性矩阵的模型量化指标体系.模型实现过程包括风险评估、风险处理、定量测量、安全事件管理和报表5个部分,并给出实施流程.应用结果表明,该模型能准确测量风险处理计...

关 键 词:ARCE测量模型  量化指标体系  风险矩阵  风险管理  风险评估  风险处理计划
收稿时间:2011-04-20

Design and Implementation of ARCE Risk Treatment Plan Measurement Model
LIU Qi,ZHUJin-e,XIE Zong-xiao,KONG Jin-sheng.Design and Implementation of ARCE Risk Treatment Plan Measurement Model[J].Computer Engineering,2011,37(19):277-279.
Authors:LIU Qi  ZHUJin-e  XIE Zong-xiao  KONG Jin-sheng
Affiliation:1.Department of Information Security,Henan Police College,Zhengzhou 450002,China;2.Fuji Electric(Hangzhou) Software Co.,Ltd.,Hangzhou 310012,China;3.Information Technology Security Evaluation Center of Shandong Province,Jinan 250000,China;4.School of Electrical Engineering,Zhengzhou University,Zhengzhou 450002,China)
Abstract:This paper proposes a novel model called ARCE(Assets Risk Value Control Measures Effectiveness).Correctness of the model is proved theoretically.A quantitative ARCE index system is proposed,with the input of organization's information security assets risk value and control measure implemented,and the output of risk treatment plan effectiveness matrix through intermediate variable matrix.The implementation process of the model includes risk assessment,risk treatment,quantitative measurement,security event management and report five modules.It introduces the implementation pseudo code and flow of application for ARCE model,gives an example of implementing this model in some organization.The superiorities of implementing this model are measuring risk treatment plan's effectiveness accurately,using preventive measures to improve organizations' security.
Keywords:Assets Risk Value & Control Measures Effectiveness(ARCE) measurement model  quantitative index system  risk matrix  risk management  risk assessment  risk treatment plan
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机工程》浏览原始摘要信息
点击此处可从《计算机工程》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号