作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (23): 15-17. doi: 10.3969/j.issn.1000-3428.2006.23.006

• 博士论文 • 上一篇    下一篇

一种有效的风险评估模型、算法及流程

裴尔明1,2,刘宝旭1   

  1. (1. 中国科学院高能物理所计算中心,北京 100049;2. 中国科学院研究生院,北京 100049)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2006-12-05 发布日期:2006-12-05

Effective Risk Assessment Model、Algorithm and Process

PEI Erming 1,2, LIU Baoxu1   

  1. (1. Computing Center, Institute of High Energy Physics, Chinese Academy of Sciences, Beijing 100049; 2. Graduate School of Chinese Academy of Sciences, Beijing 100049)
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-12-05 Published:2006-12-05

摘要: 风险评估作为信息安全管理流程中最关键的步骤之一,需要一套科学的模型来保证其有效实施。研究和制定风险评估的模型、算法和流程成为当前研究的热点问题。该文依据ISO/IEC通用标准及一些商用标准,提出了一种较为科学且行之有效的风险评估模型和算法,并且描述了风险评估的流程,对组织自评估有很好的参考意义。

关键词: 风险评估, 模型, 算法

Abstract: As one of the key steps of IT security management, risk assessment, on which more and more attention is paid, needs an scientific model to guarantee its effective implementation. This article, according to a series of ISO/IEC and commercial standards, introduces an effective risk assessment model and its algorithm, describes the steps of implementation, which offers a good reference to organizing self-assessment.

Key words: Risk assessment, Model, Algorithm