A case study on risk management of enterprise information security

Jingyan Wang, Zhen Cai Zhu, Weigang Guo, Jianqin Xie · 2012

Based on the construction of enterprise information security system, this paper discusses the concept of information security, information security management and information security risk management, introduces the system framework of information security system and the constructing procedure of information security risk management system. In the risk appraising process, risk factors are sorted by use of comparison matrix. The risk handling scheme is designed in accordance with the priority principle, and is implemented in two stages. The practice has proved that it is necessary to face the risk actively, early knowing, early recognizing and early controlling. Only in this way enterprise can effectively reduce risk probability, or decrease the loss once risk occurs.

Read the paper · More papers on PaperTik