基于IRA-CMM模型的风险评估管理及改进
Infosec Risk Assessment Managing and Improving Based on
IRA-CMM Model
摘要 信息安全风险评估规范以及相关指南指导了风险评估工作,但在评估过程管理和评估能力改进方面还缺乏系统的理论支持。回顾了目前的信息安全风险评估现状,分析了其中存在的问题;基于信息系统生命周期和系统安全工程相关模型,提出了三维的风险评估能力成熟度模型(IRA-CMM);将该模型应用于风险评估过程管理和评估能力改进。
关键词 信息安全 风险评估 能力成熟度模型 过程管理 能力改进
Abstract: The risk assessment specification for information security and other related
operation guides greatly help people to carry out risk assessment, but there is a lack of
systematically theoretical support in the view of assessment process manageing and
capacity improving. The paper summarizes the current development in information
system security risk assessment, and analyzes some practical problems to be solved.
Then based on information system life cycle and system security engineer model, a new
three-dimension information risk assessment capacity maturity model (IRA-CMM) is
suggested. In the end,the IRA-CMM model is applied in information security assessment
process managing and capacity improving.
Keywords: information security; risk assessment; CMM; process managing; capacity
improving
本期目录
- 版式技术产业应用联盟成立催生产业标准
- 全国信息安全标准化工作有序、有力开展
- 业内信息
- 基于IRA-CMM模型的风险评...
- GB/T 15532...
- 标准化—规范和引导信息服务业发...
- LED加速寿命试验方法的研究 ...
- Web服务寻址标准互操作性分析...
- 基于H.264/AVC的3G视...
- 高集成非易失性FPGA平台的安...
- LED光辐射安全及标准进展 ...
-
SOA标准选型研究
... - RFID测试标准和测试技术研究...
- IEC 61169-...
- 钢铁业MES系统整合技术 <...
- 基于ISO 2700...
- 数字版权管理领域专利分析 <...
- LoadRunner在软件性能...