论文部分内容阅读
信息系统风险评估是信息安全保障机制建立过程中的重要评价方法和决策机制,已成为国际上考察信息系统安全性的一个重要环节。文中针对信息系统风险评估提出了一种基于威胁模型的评估方法,通过对信息系统中涉及关键资产的数据流构建STRIDE威胁模型来识别威胁,并量化威胁发生的可能性和严重程度,从而进一步评估信息系统的安全风险。
Information system risk assessment is an important evaluation method and decision-making mechanism in the process of establishment of information security assurance mechanism. It has become an important link in the international study of information system security. In this paper, an assessment method based on threat model is proposed for information system risk assessment. The STRIDE threat model is constructed to identify the threat and quantify the probability and severity of the threat. Information system security risks.