|
With the development of information technology, information systems in the country's political, military and economic fields widely used throughout society increasingly dependent on information systems, information systems security issues have become stable economic relations and national security social problems. The information system for effective risk assessment, selection of effective preventive measures, proactive information security threats to information systems is to solve the crux of the problem. Since the information system components and logical complexity of the relationship, coupled with China's current information security risk assessment work has just started, the specific assessment methods, index system, supporting software is far from perfect, or lack of reality operability. In this paper, the value of assets in risk assessment, vulnerability and assessment of threats to assets, we propose a new with good operability risk assessment methods. Article is based on our \, and in assessing the value of the assets when assessed against the CIA triad adds weight indicator. In addition, the assessment of vulnerability and threat to add more reference. For example, in vulnerability assessment, you must refer to its affiliation with the asset exposure levels, the technology to achieve the degree of difficulty. In the assessment of the threat, we must refer to the degree of risk the threat of the assets of the institution's risk level, attack restoration costs, prevention costs, and the threat name, threatening object, such as the main threat. Article Delphi method used to build expert scoring model, the model is applied on the value of assets (including confidentiality, integrity, availability), threats and vulnerabilities and other factors to score. Based on expert knowledge and experience, after several rounds of consultation, feedback and adjustments to estimates closer to the true value, the result is more authoritative, high reliability and validity. Article using correlation analysis between the risk assessment factors, regression analysis using the sample data of the experts for the overall score estimation, the overall estimated risk calculations and the overall regression equation regression model and parameters through the model test and tests to ensure its accuracy sex, to some extent, solve the problem of quantitative risk assessment. This study is divided into six parts, the first part of the article discusses the research background, aims and methods, review of the domestic and international information security risk assessment on current research and risk assessment purpose and meaning. Based on the second part of our \model, the risk assessment process, risk analysis principles and methods of evaluation. The third part of the Delphi method was constructed based on expert ratings of information security risk assessment model, by building expert, the expert score on the asset value, vulnerability, threat and risk assessment of the risk assessment of sample data. The fourth part is the empirical research, the third part of the model is applied to build an expert assessment of Guangxi Unicom BSS systems, in strict accordance with the second part of the introduction of risk assessment methods and procedures, the selection of BSS systems were carried out as a key asset value of the assets, vulnerability, threat risk assessment for risk assessment sample data; fifth part continue to complete the empirical research, the correlation and regression analysis methods integrated use, using SPSS software is based on the fourth part of the experts rated the sample data and the estimated regression equation regression model, and through the model test and parametric test the feasibility of its equation. Part VI of this study are summarized, presented research work and plan the next step.
|