首页 | 本学科首页   官方微博 | 高级检索  
     

考虑成本与要素关系的信息安全风险分析模型
引用本文:赵刚,宫义山,王大力.考虑成本与要素关系的信息安全风险分析模型[J].沈阳工业大学学报,2015,37(1):69-74.
作者姓名:赵刚  宫义山  王大力
作者单位:北京信息科技大学 信息管理学院, 北京 100192
基金项目:国家“十二五”科技支撑计划项目(2012BAH08B02);国家自然科学基金资助项目(61272513);北京市自然科学基金资助项目(4132011)
摘    要:针对信息安全风险评估问题,提出了同时考虑风险要素关系和控制措施作用及成本的风险分析模型.与现有研究成果相比,该风险分析模型的优势在于充分考虑威胁和脆弱性等风险要素相互关系的基础上,更加注重控制措施对威胁和脆弱性等风险要素的影响关系,同时考虑风险处理时控制措施的成本,为风险评估提供更加客观、准确的风险分析方法和有效的控制措施选择与优化策略.案例分析结果表明,利用该多目标决策风险分析模型能够有效地量化风险评估要素间的影响关系,依据控制措施的有效程度和合理成本提供客观、准确的控制措施优选排序,提高风险评估的准确性,从而为信息安全风险管理提供科学的决策依据.

关 键 词:风险评估  风险要素相互关系  控制措施选择  成本  多目标决策  信息安全  决策试验和评价实验法  逼近理想求解的排序法  

Information security risk analysis model considering costs and factors relevance
ZHAO Gang;GONG Yi-shan;WANG Da-li.Information security risk analysis model considering costs and factors relevance[J].Journal of Shenyang University of Technology,2015,37(1):69-74.
Authors:ZHAO Gang;GONG Yi-shan;WANG Da-li
Affiliation:School of Information Management, Beijing Information Science and Technology University, Beijing 100192, China
Abstract:Aiming at the information security risk assessment, a risk analysis model considering relevance among risk factors and controls with costs was proposed. Compared with the present research results, the proposed method not only fully considers the interrelation between the threats and vulnerabilities, but also concentrates on the influence of controls on such risk factors as threats and vulnerabilities, and simultaneously pays attention to the costs of risk treatment controls, which provides more objective and accurate method for risk assessment and effective strategy for control selection and optimization. The results of case analysis show that the proposed risk analysis model based on multi objective decision making can effectively quantize the interrelations among the risk assessment factors, provide the objective and accurate priority orders for control optimization according to the efficiency and rational costs of the controls, improve the accuracy of risk assessment, and thus provide the scientific decision making evidence for the information security risk management. 
Keywords:risk assessment  interrelation of risk factor  controls-selecting  cost  multi-objective decision making  information security  decision making test and evaluation test  ordering method approximate to ideal solution
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《沈阳工业大学学报》浏览原始摘要信息
点击此处可从《沈阳工业大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号