摘要
分析了目前几种比较典型的信息安全管理模型存在的不足,提出了信息安全风险管理模型EPDCA,论述了该模型的理论依据、模型构成和模型中的各个组成内容的主要功能。研究结果表明:该模型具有良好的动态性、循环性和可行性,能够实现信息安全风险管理的全过程控制。
After analyzing the disadvantages of some representative models used for information security management, the EPDCA model for risk management of information security was developed. Hence then, the theoretical basis, model structure and main function of each parts of model were discussed. The results of this study showed that model has good performance in dynamic, recycling and availability, the whole process control of risk management of information security can be realized with this model.
出处
《工业工程与管理》
2008年第2期14-18,共5页
Industrial Engineering and Management