A Scenario-Based Information Security Risk Evaluation Method

被引:1
|
作者
Ban, Xiaofang [1 ]
Tong, Xin [1 ]
机构
[1] China Informat Technol Secur Evaluat Ctr, Syst Evaluat Div, Beijing, Peoples R China
关键词
risk evaluation; risk scenario; business impact; vulnerabilities; asset value chain; risk integration;
D O I
10.14257/ijsia.2014.8.5.03
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Risk evaluation is the core process of information security risk management. An effective risk evaluation can protect organizations and maintain their abilities to carry out missions and activities against threats as well as helping to implement controls and safeguards that are actually needed. While the traditional information security risk evaluation approaches are lack of granular analysis and clear expression of security characteristics of risk, such as the possibility, attack path, and business impact. This paper presents the scenario-based information security risk evaluation method, based on the thought of Advanced Persistent Threat (APT) attack, by constructing risk scenario, evaluate information system security risk status. The separation analysis of the technical impact and business impact contribute to the technicians and business decision makers to grasp system risk status from their respective responsibilities. In the end of the paper, we propose a practical risk scenario construction example, which provides scientific and effective guidance for the preparation of a risk evaluation report.
引用
收藏
页码:21 / 30
页数:10
相关论文
共 50 条
  • [21] Scenario-based IT Risk Assessment in Local Government
    Mcube, Unathi
    Gerber, Mariana
    Von Solms, Rossouw
    2016 IST-AFRICA WEEK CONFERENCE, 2016,
  • [22] A scenario-based procedure for seismic risk analysis
    Kluegel, J.-U.
    Mualchin, L.
    Panza, G. F.
    ENGINEERING GEOLOGY, 2006, 88 (1-2) : 1 - 22
  • [23] Evaluation of scenario-based modularization for lifecycle design
    Umeda, Yasushi
    Fukushige, Shinichi
    Tonoike, Keita
    CIRP ANNALS-MANUFACTURING TECHNOLOGY, 2009, 58 (01) : 1 - 4
  • [24] Domain ontology for scenario-based hazard evaluation
    Wu Chong-guang
    Xu Xin
    Zhang Bei-ke
    Na Yuong-liang
    SAFETY SCIENCE, 2013, 60 : 21 - 34
  • [25] Simplified method for scenario-based risk assessment adaptation planning in the coastal zone
    Kirshen, Paul
    Merrill, Samuel
    Slovinsky, Peter
    Richardson, Norman
    CLIMATIC CHANGE, 2012, 113 (3-4) : 919 - 931
  • [26] Simplified method for scenario-based risk assessment adaptation planning in the coastal zone
    Paul Kirshen
    Samuel Merrill
    Peter Slovinsky
    Norman Richardson
    Climatic Change, 2012, 113 : 919 - 931
  • [27] A Scenario-based Modeling Method for Crossover Services
    Xi, Meng
    Yin, Jianwei
    Wei, Yongna
    Zhang, Maolin
    Deng, Shuiguang
    Li, Ying
    2020 IEEE 13TH INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (SCC 2020), 2020, : 20 - 29
  • [28] A Scenario-based Model for Resource Allocation with Price Information
    Ghiyasi, Mojtaba
    Dehnokhalaji, Akram
    FOUNDATIONS OF COMPUTING AND DECISION SCIENCES, 2021, 46 (04) : 339 - 360
  • [29] Scenario-based information retrieval in a medical digital library
    Chu, WW
    Johnson, D
    Zhu, QH
    Kangarloo, H
    2000 KYOTO INTERNATIONAL CONFERENCE ON DIGITAL LIBRARIES: RESEARCH AND PRACTICE, PROCEEDINGS, 2000, : 440 - 448
  • [30] HIV/STI Risk Communication The Effects of Scenario-based Risk Information and Frequency-based Risk Information on Perceived Susceptibility to Chlamydia and HIV
    Mevissen, Fraukje E. F.
    Meerteens, Ree M.
    Ruiter, Robert A. C.
    Feenstra, Hans
    Schaalma, Herman P.
    JOURNAL OF HEALTH PSYCHOLOGY, 2009, 14 (01) : 78 - 87