A Survey of Information Security Risk Evaluation
Zhenzhen Wang · Information Security and Communications Privacy · 2007
In information age the purpose of information risk management is to balance security cost and security level , control risk to a acceptable extent, and protect information and relative assets The two important aspects and technological research hotspots. of information risk management includes risk evaluation and risk control. This paper discusses the conception and common criteria for information system risk management, and introduces the most popular methods in the information evaluation and risk control field, including the aspects for in-depth research.