摘要
针对计算机系统的安全性事件,笔者从预防处理能力、应急处理能力和影响性等多个维度出发,提出了一种基于事件分析的安全度量方法,通过相关映射关系,简单快速地对各类信息安全事件进行定量、定性的度量分析,在宏观上对安全体系做出快速、高效的风险评估,抓住重点,及时发现存在的风险薄弱点,为后续开展信息系统安全体系建设工作提供依据并指明方向。
Aiming at the security events of computer system,the author puts forward a security measurement method based on event analysis from the aspects of prevention,emergency and influence.Through the correlation mapping,the author simply and quickly conducts quantitative and qualitative measurement and analysis of various information security events,and makes rapid and efficient risks to the security system at a macro level Evaluate,grasp the key points,find out the weak points of risks in time,and provide basis and direction for the follow-up construction of information system security system.
作者
孙书彤
Sun Shutong(China Unionpay Co.,Ltd.,Shanghai 201201,China)
出处
《信息与电脑》
2020年第10期216-219,共4页
Information & Computer
关键词
信息系统
安全事件
度量方法
information system
security event
measurement method