earticle

논문검색

A Hierarchical Information System Risk Evaluation Method Based on Asset Dependence Chain

원문정보

초록

영어

The current information security risk evaluation methods are only concerned with the risk of system components, rarely based on business risk perspective. Thus, it is difficult to meet different levels of information security risk comprehension such as the operational staff and the organization's manager. This paper proposes a hierarchical risk evaluation method based on asset dependence chain to quantify the hierarchical risk, the information systems security risks are divided into three levels: the component level, system level and organizational level. By analyzing the assets dependence in three levels, a "business systems-information systems-system components" assets dependence chain is formed. In the end, a hierarchical risk calculation method is presented. The risk analysis result can reflect the level of security risk evaluation needs more comprehensively and objectively.

목차

Abstract
 1. Introduction
 2. Risk Factors Analyses
  2.1. Asset Analysis
  2.2. Vulnerabilities Analyses
  2.3. Threat Analysis
  2.4. Control Measures Analysis
 3. Risk Calculation Method
 4. Conclusions
 References

저자정보

  • Xin Tong China Information Technology Security Evaluation Center, Beijing, China
  • Xiaofang Ban China Information Technology Security Evaluation Center, Beijing, China

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.