论文部分内容阅读
IT安全是一个永远的话题,但即便发展了这么多年,仍然无法防止问题的产生,一个个安全事故让人触目惊心。信息安全风险评估的产生,正是为了进行预防判断,阻止风险演变成事故。在我国,风险评估才刚刚起步,但在国家的支持和企业的关注下,正在良性发展。评估是要求,也是一种趋势,我们需要风险评估文化来让人们逐渐了解它、掌握它、利用它。最终,风险评估应当与IT安全规划结合起来,防患于未然,并与执行结合起来,形成一个健全的安全防护循环。这才是解决安全问题的法门。
IT security is an eternal topic, but even after many years of development, it still can not prevent the problems from occurring. It is astonishing that one security accident has occurred. The emergence of information security risk assessment is precisely for the prevention of judgments to prevent the risk evolved into an accident. In our country, the risk assessment has just started, but it is developing soundly with the support of the state and the concern of the enterprises. Assessment is a requirement, but also a trend. We need a risk assessment culture to get people to understand it, master it, and use it. Ultimately, the risk assessment should be integrated with the IT security plan to prevent problems and combine them with enforcement to create a robust security loop. This is the way to solve the security problem.