首页 | 本学科首页   官方微博 | 高级检索  
     

组合对象信息安全风险评估研究
引用本文:王连强,吕述望,张剑,刘振华. 组合对象信息安全风险评估研究[J]. 计算机工程与应用, 2006, 42(26): 17-19
作者姓名:王连强  吕述望  张剑  刘振华
作者单位:南开大学信息技术科学学院,天津,300071;中国科学院研究生院信息安全国家重点实验室,北京,100080;中国科学院研究生院信息安全国家重点实验室,北京,100080;北京理工大学软件学院,北京,100081
基金项目:国家自然科学基金;国家重点基础研究发展计划(973计划)
摘    要:风险评估已经成为信息安全管理的重要组成部分,其方法的选择直接影响着风险结果的准确性和客观性,进而会影响到组织的整体信息安全水平。目前很多评估方法仅能对单个资产的威胁和脆弱性进行分析,并直接采用调查问卷或矩阵的方式得到风险,而没有从面向对象的角度给出威胁相对于系统的客观的整体风险值。论文提出了一种针对组合对象的定性与定量相结合的风险评估方法,有效解决了上述问题,并给出了合理的风险计算公式。

关 键 词:信息安全  风险评估  威胁  脆弱性
文章编号:1002-8331-(2006)26-0017-03
收稿时间:2006-07-01
修稿时间:2006-07-01

A Study of Risk Assessment Related to Information Security Based on Combined Objects
WANG Lian-qiang,LV Shu-wang,ZHANG Jian,LIU Zhen-hua. A Study of Risk Assessment Related to Information Security Based on Combined Objects[J]. Computer Engineering and Applications, 2006, 42(26): 17-19
Authors:WANG Lian-qiang  LV Shu-wang  ZHANG Jian  LIU Zhen-hua
Affiliation:College of Information Technical Science, Nankai University,Tianjin 300071 ;State Key Laboratory of Information Security,Graduate University of Chinese Academy of Sciences,Beijing 100080;Software College,Beijing University of Technology,Beiiing 100081
Abstract:Risk assessment has become an important part of information security management process.The method for risk assessment impacts the veracity and objectivity of the results,and also impacts the overall information security capacity of the organization.At present,many assessment methods only analyze threats and vulnerabilities of single asset,and the means to acquire the risk is questionnaires or matrix.They don't provide systematic and objective risk value based on objects.This paper presents a method of risk assessment based on combined objects,which adopts qualitative and quantitative means.This method resolves those problems and provides reasonable formula for computing the risk value.
Keywords:information security  risk assessment  threat  vulnerability
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号