1The International Organization for Standardization. Common criteria for information technology security evaluation [J]. ISO/IEC15408, 1999 (E).
2S P Bennett, M P Kailay. An application of qualitative risk analysis to computer security for the commercial sector [J ]. Information Security Technical Report, 2001 (6).
3Gordon. The economics of information security investment [J]. ACM Transactions on Information and System Security, 2002 (5).