节点文献

一种面向业务的信息安全风险评估方法

A Risk Assessment Method for the Security of Applied Systems

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 詹锋

【Author】 ZHAN Feng (School of Computer, Electronics and Information, Guangxi University, Nanning, Guangxi, 530004,China)

【机构】 广西大学计算机与电子信息学院

【摘要】 根据信息安全风险评估理论提出一种面向业务的风险评估方法。该方法明确将各类业务系统作为整体安全对象进行风险评估,并应用“故障树”方法对业务系统进行风险建模和风险计算。该方法是一种行之有效.易于操作的安全评估方法。

【Abstract】 A risk evaluation method for applied systems in security is presented in terms of risk assessment knowledge of information systems. In this method, any applied system is considered as a whole object in security to be assessed. The "Fault tree analysis" is used to setup a risk model and to do risk calculation. The method is applied to concrete project of security evaluation. The result reveals that it is effective and easy in operation.

【基金】 广西留学回国人员科学基金项目(桂科回0342001);广西科技攻关项目(桂科攻0385001)联合资助。
  • 【会议录名称】 广西计算机学会2006年年会论文集
  • 【会议名称】广西计算机学会2006年年会
  • 【会议时间】2006-11
  • 【会议地点】中国广西
  • 【分类号】TP309
  • 【主办单位】广西计算机学会
节点文献中: