期刊论文详细信息
Bezopasnostʹ Informacionnyh Tehnologij
Methods and means of analysis of risks of the information security of the enterprise
Damir Faritovich Fayzulayev1  Boris Borisovich Morozov1 
[1] Astrakhan State University;
关键词: CORAS;    CRAMM;    Microsoft Security Assessment Tool (MSAT);    OCTAVE;    RiskWatch;    GRIF;    information security analysis;    analysis and assessment of IS risks;    information security;    methods and means of IS risk assessment;   
DOI  :  10.26583/bit.2017.3.09
来源: DOAJ
【 摘 要 】

Methods and means of assessing information security risks are considered. The main problems that arise in the process of performing the analysis of the security of an enterprise in the field of information security are shown. A brief review of the existing instrumental solutions to the problems of assessing the risks of information security organizations engaged in various fields of activity is given. The main advantages and disadvantages of methods for risk assessment and software based on these techniques are analyzed. The results of the review are presented, conclusions are made regarding the shortcomings of methods and tools, and the question of the optimal correlation of such concepts as the breadth of applicability of methods and software tools and reliability, accuracy and adequacy of information security risk assessment are considered. We propose new additional stages of risk analysis that allow improving existing methods and eliminating the shortcomings identified during the review.

【 授权许可】

Unknown   

  文献评价指标  
  下载次数:0次 浏览次数:0次