A Scenario-Based Information Security Risk Evaluation Method

被引:1
|
作者
Ban, Xiaofang [1 ]
Tong, Xin [1 ]
机构
[1] China Informat Technol Secur Evaluat Ctr, Syst Evaluat Div, Beijing, Peoples R China
关键词
risk evaluation; risk scenario; business impact; vulnerabilities; asset value chain; risk integration;
D O I
10.14257/ijsia.2014.8.5.03
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Risk evaluation is the core process of information security risk management. An effective risk evaluation can protect organizations and maintain their abilities to carry out missions and activities against threats as well as helping to implement controls and safeguards that are actually needed. While the traditional information security risk evaluation approaches are lack of granular analysis and clear expression of security characteristics of risk, such as the possibility, attack path, and business impact. This paper presents the scenario-based information security risk evaluation method, based on the thought of Advanced Persistent Threat (APT) attack, by constructing risk scenario, evaluate information system security risk status. The separation analysis of the technical impact and business impact contribute to the technicians and business decision makers to grasp system risk status from their respective responsibilities. In the end of the paper, we propose a practical risk scenario construction example, which provides scientific and effective guidance for the preparation of a risk evaluation report.
引用
收藏
页码:21 / 30
页数:10
相关论文
共 50 条
  • [31] Emerging technologies in civil security-A scenario-based analysis
    Bierwisch, Antje
    Kayser, Victoria
    Shala, Erduana
    TECHNOLOGICAL FORECASTING AND SOCIAL CHANGE, 2015, 101 : 226 - 237
  • [32] Method of Determine Index Weight in Security Risk Evaluation Based on Information Entropy
    Xiong Jin-shi
    Li Jian-hua
    Yang Ying-hui
    2012 FOURTH INTERNATIONAL CONFERENCE ON MULTIMEDIA INFORMATION NETWORKING AND SECURITY (MINES 2012), 2012, : 43 - 48
  • [33] Smart grid information security evaluation method based on risk weight algorithm
    Li, He
    Zhang, Zhiang
    Sun, Jia
    Qi, Ziyi
    Min, Yue
    Qi, Zhi
    INTERNATIONAL CONFERENCE ON ALGORITHMS, HIGH PERFORMANCE COMPUTING, AND ARTIFICIAL INTELLIGENCE (AHPCAI 2021), 2021, 12156
  • [34] Context-Specific, Scenario-Based Risk Scales
    Yu, Michael
    Lejarraga, Tomas
    Gonzalez, Cleotilde
    RISK ANALYSIS, 2012, 32 (12) : 2166 - 2181
  • [35] Bias, exploitation and proxies in scenario-based risk minimization
    Mausser, Helmut
    Romanko, Oleksandr
    OPTIMIZATION, 2012, 61 (10) : 1191 - 1219
  • [36] Robust scenario-based value-at-risk optimization
    Oleksandr Romanko
    Helmut Mausser
    Annals of Operations Research, 2016, 237 : 203 - 218
  • [37] Learning risk factors for suicide: A scenario-based activity
    Madson, L
    Vas, CJ
    TEACHING OF PSYCHOLOGY, 2003, 30 (02) : 123 - 126
  • [38] Scenario-based threat metric evaluation based on the highd dataset
    Schneider, Patrick
    Butz, Martin
    Heinzemann, Christian
    Oehlerking, Jens
    Woehrle, Matthias
    2020 IEEE INTELLIGENT VEHICLES SYMPOSIUM (IV), 2020, : 213 - 218
  • [39] Robust scenario-based value-at-risk optimization
    Romanko, Oleksandr
    Mausser, Helmut
    ANNALS OF OPERATIONS RESEARCH, 2016, 237 (1-2) : 203 - 218
  • [40] Scenario-based Supply Chain Network risk modeling
    Klibi, Walid
    Martel, Alain
    EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 2012, 223 (03) : 644 - 658