首页> 外文会议>Joint ASME/JSME Pressure Vessels and Piping Conference >TOWARD A RISK-BASED APPROACH TO THE ASSESSMENT OF THE SURETY OF INFORMATION SYSTEMS
【24h】

TOWARD A RISK-BASED APPROACH TO THE ASSESSMENT OF THE SURETY OF INFORMATION SYSTEMS

机译:朝着基于风险的信息方法评估信息系统的安全方法

获取原文

摘要

Traditional approaches to the assessment of information systems have treated system security, system reliability, data integrity, and application functionality as separate disciplines. However, each area's requirements and solutions have a profound impact on the successful implementation of the other areas. A better approach is to assess the "surety" of an information system, which is defined as ensuring the "correct" operation of an information system by incorporating appropriate levels of safety, functionality, confidentiality, availability, and integrity. Information surety examines the combined impact of design alternatives on all of these areas. We propose a modelling approach that combines aspects of fault trees and influence diagrams for assessing information surety requirements under a risk assessment framework. This approach allows tradeoffs to be based on quantitative importance measures such as risk reduction while maintaining the modelling flexibility of the influence diagram paradigm. This paper presents an overview of the modelling method and a sample application problem.
机译:评估信息系统的传统方法已处理系统安全,系统可靠性,数据完整性和应用程序功能作为单独的学科。但是,每个领域的要求和解决方案对其他地区的成功实施具有深远的影响。更好的方法是评估信息系统的“担保”,其被定义为通过结合适当的安全性,功能,机密性,可用性和完整性来确保信息系统的“正确”操作。信息担保审查了设计替代品对所有这些领域的综合影响。我们提出了一种建模方法,将故障树的各个方面结合在风险评估框架下评估信息担保需求的影响。这种方法允许权衡基于量化重要性措施,例如风险降低,同时保持影响图范式的建模灵活性。本文概述了建模方法和示例应用问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号