...
首页> 外文期刊>Procedia Computer Science >Risk Assessment Using NIST SP 800-30 Revision 1 and ISO 27005 Combination Technique in Profit-Based Organization: Case Study of ZZZ Information System Application in ABC Agency
【24h】

Risk Assessment Using NIST SP 800-30 Revision 1 and ISO 27005 Combination Technique in Profit-Based Organization: Case Study of ZZZ Information System Application in ABC Agency

机译:基于NIST SP 800-30修订版1和ISO 27005组合技术的基于风险的组织中的风险评估:ABC机构中ZZZ信息系统应用的案例研究

获取原文
           

摘要

Risk management is a practical step in handling risk scenarios in an organization, including in the field of information security. There are many techniques used to carry out information security risk assessments. One of them is a combination technique using ISO 27005 and NIST SP 800-30 revision 1. Previous research proved that the combination technique could be implemented in a non-profit organization (government). However, the detailed risk assessment steps are not explained clearly yet. Thus, raising the question of whether this new approach can be utilized in a common organization or not (not only non-profit but also profit organization). This research focuses on information security risk assessment by implementing the combination technique in a profit organization using semi-quantitative methods. The result, the combination technique can be used in common organizations both profit and non-profit with clear step by step translation.
机译:风险管理是处理组织(包括信息安全领域)中的风险方案的实际步骤。有许多技术可用于执行信息安全风险评估。其中之一是使用ISO 27005和NIST SP 800-30修订版1的组合技术。先前的研究证明,该组合技术可以在非营利组织(政府)中实施。但是,详细的风险评估步骤尚未明确解释。因此,提出了一种新方法是否可以在普通组织中使用的问题(不仅是非营利组织,而且还可以在营利组织中使用)。本研究的重点是通过在利润组织中使用半定量方法实施组合技术来进行信息安全风险评估。结果,结合技术可以在清晰的分步翻译中用于普通组织和非盈利组织。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号