Author Login Chief Editor Login Reviewer Login Editor Login Remote Office

Computer Engineering ›› 2006, Vol. 32 ›› Issue (2): 140-143.

• Security Technology • Previous Articles     Next Articles

Design for BS7799 Risk Assessment Method

HAN Quanyin1,2, ZHANG Yuqing1, NIE Xiaowei1,3   

  1. 1. Graduate School of Chinese Academy of Sciences, Beijing 100039; 2. School of Computer Science and Engineering, Xidian University,Xi’an 710071; 3. School of Information Science and Engineering, Yanshan University, Qinghuangdao 066004
  • Online:2006-01-20 Published:2006-01-20

BS7799 风险评估的评估方法设计

韩权印 1,2,张玉清1,聂晓伟1,3   

  1. 1. 中科院研究生院,北京 100039;2. 西安电子科技大学计算机科学与工程学院,西安 710071;3. 燕山大学信息科学与工程学院,秦皇岛 066004

Abstract: After introducing the BS7799 standard, analyzing its merits and shortage, and modeling the framework, this paper brings forward an evaluation method that applies the BS7799 standard to make information security management risk assessment —— integrating the analytical hierarchy process with fault tree analysis process. Finally, the paper offers a complete computation course.

Key words: BS7799 standard; Risk assessment; Analytical hierarchy process(AHP); Fault tree analysis(FTA)

摘要: 介绍了BS7799 国际标准的内容,对标准的组织结构进行了建模,并分析了BS7799 标准的不足。在此基础上,提出了应用BS7799管理标准对组织进行信息安全管理风险评估的评估方法,即将层次分析法和失效树法相结合的综合评估方法,并给出了完整的计算过程。

关键词: BS7799 标准;风险评估;层次分析法;失效树分析法