Information Security Risk Assessment Model Based on OCTAVE for E-Government

Xin-ming Chen, Ning Wen · 2010

Operationally Critical Threat, Asset and Vulnerability Evaluation (OCTAVE) is introduced, together with its feasibility and deficiency when used in information security risk assessing for E-Government. AHP is imported to build a Risk Assessment Model of Information Security for E-Government based on OCTAVE, the value of information assets is defined by significance, confidentiality, integrality and usability, the risk assessment procedure is divided into four phases including assets evaluation, threats evaluation, vulnerability evaluation and risk measuring, the general risk value of information assets can be calculated and its risk level can be determined. At last, a case study is given to show the feasibility of the risk assessment model.

Read the paper · More papers on PaperTik