Risk Evaluation Process Model of Information Security
Jing Liu · 2009
The risk assessment applied in information technology is the information security risk evaluation. A modeling method of security system that is suitable to description results and restriction of information and to modeling form and control of distributed system is put forward based on the analysis of the concept of security system risk evaluation in the field of information security. A model of information security evaluation process has been built based on Petri net. The process is divided into several objects, such as assets identification, threats identification, vulnerability identification and existing security control measures identification etc. and make a detailed description to each object on Petri net theory.