Research on the Calculation Method of Information Security Risk Assessment Considering Human Reliability

被引:0
|
作者
Gu, Tingyang [1 ]
Lu, Minyan [1 ]
Li, Luyi [1 ]
Li, Jiao [2 ]
机构
[1] Beihang Univ, Sch Reliabil & Syst Engn, Beijing, Peoples R China
[2] Beihang Univ, Sch Elect & Informat Engn, Beijing, Peoples R China
关键词
human Reliability; information security risk assessment; calculation method of the risk value;
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Information security risk assessment is the premise and basis for ensuring the security of information systems. Current research on risk assessment focuses on the calculation methods and assessment models of the risk value. Also, lots of automatic assessment tools have been applied to risk assessment. However, these methods didn't take human errors in risk assessment work into consideration, thus couldn't solve the problem brought by the influence of human errors on final assessment results. As a result, this paper introduces the Technique for Human Error Rate Prediction (THERP) which is a mature technique in human reliability analysis into the process of information security risk assessment. Combined with current analysis techniques of human errors in computer science and aiming at the calculation process of the risk value of important assets in information security risk assessment, research on the calculation method of risk value considering human reliability is carried out in this paper. The calculation method of human error rates in the entire process of risk value calculation is proposed. An example is provided to verify the method proposed in this paper.
引用
收藏
页码:457 / 462
页数:6
相关论文
共 50 条
  • [1] Assessment Model and Method Research of Information Security Risk
    Lu Zhen
    Xiong Zhen
    Tu Keqin
    FRONTIERS OF MANUFACTURING AND DESIGN SCIENCE IV, PTS 1-5, 2014, 496-500 : 2170 - +
  • [2] The Research of Information Security Risk Assessment Method Based on AHP
    Xu, Ning
    Zhao, DongMei
    SPORTS MATERIALS, MODELLING AND SIMULATION, 2011, 187 : 575 - 580
  • [3] Research on information system risk analysis and security situation assessment method
    Wang, Sheng
    Zhang, LinHao
    Zhang, Jie
    Tang, Yong
    Liang, YunHui
    Journal of Physics: Conference Series, 2021, 1792 (01):
  • [4] Research on Information Security Risk Assessment Method Based on Fuzzy Rule Set
    Cai, Wentian
    Yao, Huijun
    Wireless Communications and Mobile Computing, 2021, 2021
  • [5] Research on Information Security Risk Assessment Method Based on Fuzzy Rule Set
    Cai, Wentian
    Yao, Huijun
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021
  • [6] Risk Assessment of Power Grid Considering the Reliability of the Information System
    Lu, Dongxu
    Liu, Yanli
    Zeng, Yuan
    2016 IEEE INTERNATIONAL CONFERENCE ON SMART GRID COMMUNICATIONS (SMARTGRIDCOMM), 2016,
  • [7] Information Security Risk Assessment: A Method Comparison
    Wangen, Gaute
    COMPUTER, 2017, 50 (04) : 52 - 61
  • [8] Research on a Risk Assessment Method considering Risk Association
    Zhang, Zhan
    Li, Kai
    Zhang, Lei
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2016, 2016
  • [9] Risk assessment of human error in information security
    Cheng, Xiang-Yun
    Wang, Ying-Mei
    Xu, Zi-Ling
    PROCEEDINGS OF 2006 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2006, : 3573 - +
  • [10] Information security risk assessment using the AHP method
    Zaburko, J.
    Szulzyk-Cieplak, J.
    IV INTERNATIONAL CONFERENCE OF COMPUTATIONAL METHODS IN ENGINEERING SCIENCE (CMES'19), 2019, 710