A case study on risk management of enterprise information security
Jingyan Wang, Zhen Cai Zhu, Weigang Guo, Jianqin Xie
Abstract
Jingyan Wang, Zhen Cai Zhu, Weigang Guo, Jianqin Xie
Abstract
Based on the construction of enterprise information security system, this paper discusses the concept of information security, information security management and information security risk management, introduces the system framework of information security system and the constructing procedure of information security risk management system. In the risk appraising process, risk factors are sorted by use of comparison matrix. The risk handling scheme is designed in accordance with the priority principle, and is implemented in two stages. The practice has proved that it is necessary to face the risk actively, early knowing, early recognizing and early controlling. Only in this way enterprise can effectively reduce risk probability, or decrease the loss once risk occurs.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Based on the construction of enterprise information security system, this paper discusses the concept of information security, information security management and information security risk management, introduces the system framework of information security system and the constructing procedure of information security risk management system. In the risk appraising process, risk factors are sorted by use of comparison matrix. The risk handling scheme is designed in accordance with the priority principle, and is implemented in two stages. The practice has proved that it is necessary to face the risk actively, early knowing, early recognizing and early controlling. Only in this way enterprise can effectively reduce risk probability, or decrease the loss once risk occurs.
Key concepts: Computer science, Risk management, Information security, Information security management, Risk analysis (engineering), Computer security, Knowledge management, Business