资源描述:
《一个识别信息安全风险的整体风险分析方法【外文翻译】》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、毕业论文外文翻译原文AHOLISTICRISKANALYSISMETHODFORDENTIFYINGINFORMATIONECURITYRISKJanineL.SpearsThePennsylvaniaStateUniversity,SmealCollegeofBusiness,UniversityPark,PA16802Abstract:Riskanalysisisusedduringtheplanningofinformationsecuritytoidentifysecurityrequireme
2、nts,andisalsooftenusedtodeterminetheeconomicfeasibilityofsecuritysafeguards.Thetraditionalmethodofconductingariskanalysisistechnology-drivenandhasseveralshortcomings.First,itsfocusontechnologyisatthedetrimentofconsideringpeopleandprocessesassignificantso
3、urcesofsecurityrisk.Second,ananalysisdrivenbytechnicalassetscanbeoverlytime-consumingandcostly.Third,thetraditionalriskanalysismethodemployscalculationsbasedlargelyonguessworktoestimateprobabilityandfinanciallossofasecuritybreach.Finally,anIT-centricappr
4、oachtosecurityriskanalysisdoesnotinvolvebusinessuserstotheextentnecessarytoidentifyacomprehensivesetofrisks,ortopromotesecurityawarenessthroughoutanorganization.Thispaperproposesanalternative,holisticmethodtoconductingriskanalysis.Aholisticriskanalysis,a
5、sdefinedinthispaper,isonethatattemptstoidentifyacomprehensivesetofrisksbyfocusingequallyontechnology,information,people,andprocesses.Themethodisdrivenbycriticalbusinessprocesses,whichprovidesfocusandrelevancetotheanalysis.Keyaspectsofthemethodincludeabus
6、iness-drivenanalysis,userparticipationtheanalysis,architectureanddataflowdiagramsasameanstoidentifyrelevantITassets,riskscenariostocaptureproceduralandsecuritydetails,andqualitadveesdmadon.Themixtureofpeopleandtoolsinvolvedintheanalysisisexpectedtoresult
7、inamorecomprehensivesetofidendfiedrisksandasignificantincreaseinsecurityawarenessthroughouttheorganizadon.Keywords:riskanalysis,informadonsecurity,riskmanagement,businessprocess,dataflowdiagram,riskscenario.1.INTRODUCTIONManaginginformationsecurityisesse
8、ntiallymanagingaformofrisk.Themanagementofriskgenerallyinvolvesconductingariskanalysistoidentifyandevaluaterisks,andthenemployingriskmanagementtechniquestomitigateorreduceriskswheredeemedappropriate.Likewise,thestandardapp