首页> 外文期刊>Issues in Informing Science and Information Technology >Improving Information Security Risk Analysis Practices for Small- and Medium-Sized Enterprises: A Research Agenda
【24h】

Improving Information Security Risk Analysis Practices for Small- and Medium-Sized Enterprises: A Research Agenda

机译:中小企业信息安全风险分析实践的改进:研究议程

获取原文
           

摘要

Despite the availability of numerous methods and publications concerning the proper conduct of information security risk analyses, small and medium sized enterprises (SMEs) face serious organizational challenges managing the deployment and use of these tools and methods to assist them in selecting and implementing security safeguards to prevent IS security compromises. This paper builds a case for and then outlines a possible approach and a multi-faceted research agenda for developing an “open development” strategy to address recognized deficiencies in the area of risk analysis to include developing: a multi-level risk assessment methodology and set of decision heuristics designed to minimize the intellectual effort required to conduct SME infrastructure level risk assessments, a set of decision heuristics to assist in the quantification of organizational costs, financial as well as non-financial, a knowledge base of probability estimates associated with specified classes of threats for use in the application of the aforementioned methodology and automated tool(s) capable of supporting the execution of the aforementioned methodology and heuristics.
机译:尽管有许多关于信息安全风险分析正确进行的方法和出版物,但是中小型企业(SME)在管理部署和使用这些工具和方法以帮助他们选择和实施安全防护措施时面临着严峻的组织挑战。防止IS安全受损。本文提出了一个案例,然后概述了开发“开放式开发”策略以解决风险分析领域公认的缺陷的可能方法和多方面研究议程,其中包括开发:多级风险评估方法和方法旨在最大程度地减少进行SME基础设施级别风险评估所需的智力工作的决策启发方法,一组有助于量化组织成本,财务和非财务成本的决策启发方法,与特定类别相关的概率估计的知识库用于支持上述方法论和自动工具的威胁的自动化工具,这些工具可以支持上述方法论和启发式方法的执行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号