计算机工程与应用 ›› 2011, Vol. 47 ›› Issue (10): 217-223.

• 工程与应用 • 上一篇    下一篇

基于业务活动状态分析的风险评估研究

沙海亮,郑贵周,王声远,陈 钟   

  1. 北京大学 软件与微电子学院,北京 102600
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2011-04-01 发布日期:2011-04-01

Business activities status-based risk assessment research

SHA Hailiang,ZHENG Guizhou,WANG Shengyuan,CHEN Zhong   

  1. School of Software and Microelectronics,Peking University,Beijing 102600,China
  • Received:1900-01-01 Revised:1900-01-01 Online:2011-04-01 Published:2011-04-01

摘要: 为精确计量威胁发生可能导致的影响,提出了一种基于业务活动状态变化的信息安全风险计算方法。该方法将威胁发生对业务的影响归结为求解信息系统的业务活动的状态跃迁,以及这种跃迁导致的业务流程时间延迟问题,并以延迟时间为基准来度量业务影响。业务流程时间是最关键的业务运营绩效指标之一,这确保了该方法具备工程实践意义。最后,通过应用实例分析结果,证明了提出的风险计算方法的精确性。

关键词: 信息安全, 风险评估, 业务流程, 业务风险

Abstract: In order to accurately evaluate the impact to business,which is from the risk of information security,this paper provides a method based on the state changes of business activities.This method explains the impact that the state transition of information system makes the delay of business procedure when this risk is being solved,and makes the delay as a benchmark to evaluate the impact of risk to business.The business procedure delay is one of the most critical indicators.In the end,this paper proves the accuracy of this method by the analysis of example.

Key words: information security, risk evaluation, business process, business risk