透過您的圖書館登入
IP:3.147.61.142
  • 會議論文
  • OpenAccess

基於資訊安全管理系統構架之自動風險評估

摘要


隨著資訊科技的普及與快速發展,資訊安全已成為不容忽視的議題;多數機構著手建構資訊安全管理系統以防護其資訊安全。然而,多數此方面的研究並未針對風險評鑑方法建立自動化機制,使組織能更客觀地呈現存在的風險。本研究提出一套基於「資訊安全管理系統」構架之自動化風險評鑑技術,藉由各資產過去的風險示警記錄,以自動化方式針對目前事件進行辨識與分析,可更精確的識別威脅與弱點類型並計算風險量化數據。我們以某大型公司營運中之錄音系統為案例,進行說明及驗證。本研究藉由自動化的優點,以客觀的、有系統的、具重複性的方式,可發現人工作業無法發現的問題,進而提高資訊安全管理之品質。

並列摘要


With the popularity and rapid development of information technology, information security has become a critical issue. Many organizations have been establishing their information security management strategies to protect security of their data. However, past research has not established automatic mechanisms to objectively reflect the actual risks. This study proposes an automatic risk evaluation process based on 〞Information Security Management System〞 framework. The process compares the input event against the past risk warning records. This automatic method can accurately identify the threat and vulnerability of the current event, and then compute the quantitative figures of the associated risk. A case study of a Recording Center in a large enterprise is conducted. The advantage of automation in Information Security Management System is that the automation is objective, systematic, and repeatable. Moreover, it may detect hidden problems which cannot be easily recognized by humans. Thus, our method can improve the quality of information security management.

延伸閱讀