摘要
风险分析是信息系统风险管理的重要组成部分,是建立信息系统安全管理体系的重要前提.试图探讨一套可用于定性及定量风险分析的模型,即用风险树分析法对信息系统安全事件发生概率以及导致安全事件的必要条件一风险模式进行分析,进而用风险模式、影响及危害度分析法对风险模式的危害度及风险损失进行分析,最后用风险矩阵对风险作出最后的评估与决策.
The risk analysis is an important component of risk management, and an important precondition of safety management system of information system. This paper attempts to research a set of models for qualitative and quantitative risk analysis, that is, analyze the probability of safety events of information system and the risk mode which is the prerequisite resulting in risk events by the risk tree analysis, then analyze the risk loss and the criticality of risk mode by RMECA; finally make risk assessment and decision by risk matrix.
出处
《计算机工程》
CAS
CSCD
北大核心
2001年第3期131-132,186,共3页
Computer Engineering