Survey of Information Security Risk Assessment Methods
Lei Yao
Abstract
Lei Yao
Abstract
Information Security Risk Assessment is crucial for the establishment process of information security system, and whether as an evaluation method or as a decision-making mechanism, is also an important part of information security research. This paper first describes the development of risk evaluation for information security both at home and abroad. Then it provides classification and summary of risk evaluation methods for information security. It also describes the in-depth analysis on the superior and inferior in the process of assessment and integrated application of various methods. Finally, in considering the development of information security in China, some urgent problems in information security evaluation work are given.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Information Security Risk Assessment is crucial for the establishment process of information security system, and whether as an evaluation method or as a decision-making mechanism, is also an important part of information security research. This paper first describes the development of risk evaluation for information security both at home and abroad. Then it provides classification and summary of risk evaluation methods for information security. It also describes the in-depth analysis on the superior and inferior in the process of assessment and integrated application of various methods. Finally, in considering the development of information security in China, some urgent problems in information security evaluation work are given.
Key concepts: Computer science, Information security management, Information security, Security information and event management, Risk analysis (engineering), Threat, Standard of Good Practice, Information security audit