摘要
信息安全风险评估是组织信息安全的基础和前提,也是信息安全保障的重要内容。该文介绍了信息安全及其信息安全风险评估概念,然后对信息安全风险评估因素、方法进行了分析,并提出基于"资产—威胁/脆弱性"评价指数矩阵风险分析方法。
Information security risk assessment is the foundation and the precondition of information security of organization, and is important content of information security assurance. This paper outlines the concept of information security and risk assessment. Then, the elements and methods of information security assessment are analyzed. Risk Assessment Code Matrix of assets_threats_based method is introduced in the text.
出处
《计算机安全》
2008年第3期26-29,共4页
Network & Computer Security
关键词
信息安全
风险评估
威胁
脆弱性
information security
risk assessment
threats
vulnerabilities