作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2011, Vol. 37 ›› Issue (19): 277-279. doi: 10.3969/j.issn.1000-3428.2011.19.091

• 开发研究与设计技术 • 上一篇    下一篇

ARCE风险处理计划测量模型的设计与实现

刘 琦1,朱金娥2,谢宗晓3,孔金生4   

  1. (1. 河南警察学院信息安全系,郑州 450002;2. 富士电机(杭州)软件有限公司,杭州 310012; 3. 山东省信息安全测评中心,济南 250000;4. 郑州大学电气工程学院,郑州 450002)
  • 收稿日期:2011-04-20 出版日期:2011-10-05 发布日期:2011-10-05
  • 作者简介:刘 琦(1978-),女,讲师、博士,主研方向:风险测评模型,信息安全;朱金娥、谢宗晓,工程师、硕士;孔金生,教授、博士后、博士生导师

Design and Implementation of ARCE Risk Treatment Plan Measurement Model

LIU Qi 1, ZHU Jin-e 2, XIE Zong-xiao 3, KONG Jin-sheng 4   

  1. (1. Department of Information Security, Henan Police College, Zhengzhou 450002, China; 2. Fuji Electric(Hangzhou) Software Co., Ltd., Hangzhou 310012, China; 3. Information Technology Security Evaluation Center of Shandong Province, Jinan 250000, China; 4. School of Electrical Engineering, Zhengzhou University, Zhengzhou 450002, China)
  • Received:2011-04-20 Online:2011-10-05 Published:2011-10-05

摘要: 提出用于定量测量风险处理计划有效性的ARCE模型,从理论上证明该模型的正确性。以组织信息安全资产的风险值和已实施控制措施为输入,通过中间变量矩阵得到风险处理计划有效性矩阵的模型量化指标体系。模型实现过程包括风险评估、风险处理、定量测量、安全事件管理和报表5个部分,并给出实施流程。应用结果表明,该模型能准确测量风险处理计划的有效性。

关键词: ARCE测量模型, 量化指标体系, 风险矩阵, 风险管理, 风险评估, 风险处理计划

Abstract: This paper proposes a novel model called ARCE(Assets Risk Value & Control Measures Effectiveness). Correctness of the model is proved theoretically. A quantitative ARCE index system is proposed, with the input of organization’s information security assets risk value and control measure implemented, and the output of risk treatment plan effectiveness matrix through intermediate variable matrix. The implementation process of the model includes risk assessment, risk treatment, quantitative measurement, security event management and report five modules. It introduces the implementation pseudo code and flow of application for ARCE model, gives an example of implementing this model in some organization. The superiorities of implementing this model are measuring risk treatment plan’s effectiveness accurately, using preventive measures to improve organizations’ security.

Key words: Assets Risk Value & Control Measures Effectiveness(ARCE) measurement model, quantitative index system, risk matrix, risk management, risk assessment, risk treatment plan

中图分类号: