摘要
首先分析了企业信息安全风险评估的两种模式,即自评估和他评估,指出了它们的优缺点,然后讨论企业自评估的评估要素和评估原则,最后为企业自评估设计了一个实施流程,对该流程的各个环节进行了较为深入的分析,同时对该流程进行评价。
Firstly, two kinds of modes of information security risk assessment in the enterprises named self-assessment and other-assessm ent are analyzed, their advantages and disadvantages being pointed out. Then the assessment factors and principles of self-assessment are discussed. Finally , an implementation procedure for self-assessment of enterprises is designed, and each link of this procedure is carried on comparatively deep analysis, at the sa me time, this procedure is appraised.
出处
《计算机应用研究》
CSCD
北大核心
2005年第7期108-110,118,共4页
Application Research of Computers
基金
国家"863"计划资助项目(2002AA142151)
国家计算机网络与信息安全管理中心资助项目(2002研1A007)
关键词
自评估
风险
风险评估
Self-assessment
Risk
Risk Assessment