摘要
提出了一种基于风险事件分类的信息系统评估模型。模型将信息系统的单个风险事件按底层评估指标进行分类,得到底层指标风险值,然后按照评估指标的层次结构由下往上进行计算,并最终得到信息系统的综合风险值。最后,利用模糊综合评判法,在提出的模型上对一个信息系统进行评估,并得出评估结论。
A risk assessment model based on classification of risk events was proposed in this paper. In this model, each single risk event was classified into one of the bottom targets. Then the value of the bottom targets could be computed out. According to the target hierarchy, the risk value of an information system could thus be computed out. Finally, the fuzzy integrated assessment method was used in the proposed model to assess a system and get the risk value.
出处
《计算机应用》
CSCD
北大核心
2009年第10期2806-2808,共3页
journal of Computer Applications
基金
民航局科研基地863项目(2007kf003)
关键词
信息系统
信息安全
风险评估
风险事件分类
information system
information security
risk evaluation
classification of risk events