摘要
介绍了利用安全案例和证据推理评估信息系统安全风险的新方法。该方法具有两个重要特色:首先,安全案例结构化融合了各种风险要素、相关防护措施以及内在相互影响。其次,该方法便于进行性价比分析以促进有效的安全风险管理。同时,也解释了一些理论概念,并实例讲解了如何使用这个方法。此外,也比较了所提方法与其他现存风险评估方法的优缺点。
This paper describes an alternative methodology for the risk assessment of information systems security (ISS) by using Assurance Cses and Evidential Reasoning(ACER). The approach has the two important features. Firstly, the assurance case incorporates relevant risk factors, related counter measures and their interrelationships in a structured manner. Secondly, the proposed approach facilitates cost-benefit analyses to help promote efficient risk management. The paper tells of the theoretical concepts and provides operational guidance on how to implement the method. Moreover, the proposed method is compared with the other current existing risk assessment approaches,thus to evaluate their weaknesses and strengths.
出处
《信息安全与通信保密》
2010年第4期42-44,共3页
Information Security and Communications Privacy
关键词
风险评估
安全案例
证据推理
risk assessment
assurance case
evidential reasoning