Method of information system’s security level estimation using ISMS "Matrix"
Дмитро Валерійович Домарєв, Валерій Валентинович Домарєв, Сергій Дмитрович Прокопенко · Ukrainian Information Security Research Journal · 2013
Actuality of information system’s security level estimation is proved. For the offered method, the range of application, purpose and procedure are described. The procedure of the offered method consists of primary questioning of the client, determination of assets, determination of assets’ importance using verbal estimations, search for vulnerabilities of the determined assets, determination of threats resulting from found vulnerabilities, determination the found threats’ danger using verbal estimations, translation of assets’ importance and threats’ danger into quantitative estimations, risk assessment and ranking, determination of the most vulnerable assets and the most dangerous threats, ranking of vulnerabilities for every asset, production of recommendations concerning the vulnerabilities’ remediation, compilation of report. For the practical realization of the offered method, the information security management system "Matrix" is applied. Conclusion is made about the advantages of the offered method.