资源描述:
《一个识别信息安全风险的整体风险分析方法【外文翻译】》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、毕业论文外文翻译原文AHOLISTICRISKANALYSISMETHODFORDENTIFYINGINFORMATIONECURITYRISKJanineL.SpearsThePennsylvaniaStateUniversity,SmealCollegeofBusiness,UniversityPark,PA16802Abstract:Riskanalysisisusedduringtheplanningofinformationsecuritytoidentifysecurityrequirements,andisalsooft
2、enusedtodeterminetheeconomicfeasibilityofsecuritysafeguards.Thetraditionalmethodofconductingariskanalysisistechnology-drivenandhasseveralshortcomings.First,itsfocusontechnologyisatthedetrimentofconsideringpeopleandprocessesassignificantsourcesofsecurityrisk.Second,anana
3、lysisdrivenbytechnicalassetscanbeoverlytime-consumingandcostly.Third,thetraditionalriskanalysismethodemployscalculationsbasedlargelyonguessworktoestimateprobabilityandfinanciallossofasecuritybreach.Finally,anIT-centricapproachtosecurityriskanalysisdoesnotinvolvebusiness
4、userstotheextentnecessarytoidentifyacomprehensivesetofrisks,ortopromotesecurityawarenessthroughoutanorganization.Thispaperproposesanalternative,holisticmethodtoconductingriskanalysis.Aholisticriskanalysis,asdefinedinthispaper,isonethatattemptstoidentifyacomprehensiveset
5、ofrisksbyfocusingequallyontechnology,information,people,andprocesses.Themethodisdrivenbycriticalbusinessprocesses,whichprovidesfocusandrelevancetotheanalysis.Keyaspectsofthemethodincludeabusiness-drivenanalysis,userparticipationtheanalysis,architectureanddataflowdiagram
6、sasameanstoidentifyrelevantITassets,riskscenariostocaptureproceduralandsecuritydetails,andqualitadveesdmadon.Themixtureofpeopleandtoolsinvolvedintheanalysisisexpectedtoresultinamorecomprehensivesetofidendfiedrisksandasignificantincreaseinsecurityawarenessthroughouttheor
7、ganizadon.Keywords:riskanalysis,informadonsecurity,riskmanagement,businessprocess,dataflowdiagram,riskscenario.1.INTRODUCTIONManaginginformationsecurityisessentiallymanagingaformofrisk.Themanagementofriskgenerallyinvolvesconductingariskanalysistoidentifyandevaluaterisks
8、,andthenemployingriskmanagementtechniquestomitigateorreduceriskswheredeemedappropriate.Likewise,thestandardapp