Risk assessment method of information security based on threat analysis
Shuzhen Yao · Computer Engineering and Applications Journal · 2009
In the field of information security,risk assessment is the core of the risk management and control,also is the founda- tion and premises that builds up the safe system of the information system.This paper analyses the standards and process of in- formation security risk assessment,and proposes a quantitative security risk method ISSREM(Information System Security Risk E- valuation Method),based on threat analysis.ISSREM has features such as easily operative,independent,practical and the evalua- tion results comparable.And the sensitivity analysis of threaten frequency is presented,which makes the evaluation results more objective.This paper gives the calculation model of the method and the main procedures of risk evaluation using the method.Fi- nally,with examples to analyze the quantitative assessment method,this paper validates the rationality and effectiveness of the method.