A Scenario-Based Information Security Risk Evaluation Method

被引:1
|
作者
Ban, Xiaofang [1 ]
Tong, Xin [1 ]
机构
[1] China Informat Technol Secur Evaluat Ctr, Syst Evaluat Div, Beijing, Peoples R China
关键词
risk evaluation; risk scenario; business impact; vulnerabilities; asset value chain; risk integration;
D O I
10.14257/ijsia.2014.8.5.03
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Risk evaluation is the core process of information security risk management. An effective risk evaluation can protect organizations and maintain their abilities to carry out missions and activities against threats as well as helping to implement controls and safeguards that are actually needed. While the traditional information security risk evaluation approaches are lack of granular analysis and clear expression of security characteristics of risk, such as the possibility, attack path, and business impact. This paper presents the scenario-based information security risk evaluation method, based on the thought of Advanced Persistent Threat (APT) attack, by constructing risk scenario, evaluate information system security risk status. The separation analysis of the technical impact and business impact contribute to the technicians and business decision makers to grasp system risk status from their respective responsibilities. In the end of the paper, we propose a practical risk scenario construction example, which provides scientific and effective guidance for the preparation of a risk evaluation report.
引用
收藏
页码:21 / 30
页数:10
相关论文
共 50 条
  • [41] Scenario-based earthquake risk assessment for Bucharest, Romania
    Pavel, Florin
    Vacareanu, Radu
    INTERNATIONAL JOURNAL OF DISASTER RISK REDUCTION, 2016, 20 : 138 - 144
  • [42] Comparison of scenario-based software architecture evaluation methods
    Babar, MA
    Gorton, I
    11TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE, PROCEEDINGS, 2004, : 600 - 607
  • [43] ScenEval: A Benchmark for Scenario-Based Evaluation of Code Generation
    Paul, Debalina Ghosh
    Zhu, Hong
    Bayley, Ian
    arXiv,
  • [44] An Experience with Three Scenario-Based Methods: Evaluation and Comparison
    Petkovic, Dejan
    Raikundalia, Gitesh K.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2009, 9 (01): : 180 - 185
  • [45] The architecture of a tool for scenario-based software architecture evaluation
    Usman, Muhammad
    Ikram, Naveed
    10TH IEEE INTERNATIONAL MULTITOPIC CONFERENCE 2006, PROCEEDINGS, 2006, : 288 - +
  • [46] ScenEval: A Benchmark for Scenario-Based Evaluation of Code Generation
    Paul, Debalina Ghosh
    Zhu, Hong
    Bayley, Ian
    2024 IEEE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE TESTING, AITEST, 2024, : 55 - 63
  • [47] Scenario-based Evaluation of Prediction Models for Automated Vehicles
    Munoz Sanchez, Manuel
    Elfring, Jos
    Silvas, Emilia
    van de Molengraft, Rene
    2022 IEEE 25TH INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS (ITSC), 2022, : 2227 - 2233
  • [48] Scenario-Based Evaluation of Team Health Information Technology to Support Pediatric Trauma Care Transitions
    Hoonakker, Peter L. T.
    Hose, Bat-Zion
    Carayon, Pascale
    Eithun, Ben L.
    Rusy, Deborah A.
    Ross, Joshua C.
    Kohler, Jonathan E.
    Dean, Shannon M.
    Brazelton, Tom B.
    Kelly, Michelle M.
    APPLIED CLINICAL INFORMATICS, 2022, 13 (01): : 218 - 229
  • [49] Scenario-Based Usability Evaluation of Emergency Department Information System by Clinical Roles and Experience Levels
    Kim, M.
    Mohrer, D.
    Shapiro, J.
    Aguilar, V
    Genes, N.
    Baumlin, K.
    Elkin, P.
    ANNALS OF EMERGENCY MEDICINE, 2010, 56 (03) : S121 - S121
  • [50] Scenario-based Execution Method for Massively Parallel Accelerators
    Yamagiwa, Shinichi
    Zhang, Shixun
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 1039 - 1048