摘要
风险评估和风险控制措施是信息安全管理体系(ISMS)中的重要环节,而风险控制措施的引入可能引发新的潜在风险(传导风险),对如何防范传导风险进行了阐述,提出了基于PDCA改进模型的传导风险防范策略。
Risk assessment and risk control are the most important parts in Information Security Management System (ISMS). In some conditions, the introduction of risk control measures may cause new potential risk, which is called transmission risk in the article. This paper carries out on how to avoid the transmission risk and proposed the prevention strategy for it based on a modified PDCA Model.
出处
《计算机应用与软件》
CSCD
2010年第8期97-99,122,共4页
Computer Applications and Software
基金
国家高技术研究发展计划项目(2007AA010401)