张本群. 基于危险理论的电子政务系统信息安全风险评估[J]. 微电子学与计算机, 2012, 29(9): 71-73,78.
引用本文: 张本群. 基于危险理论的电子政务系统信息安全风险评估[J]. 微电子学与计算机, 2012, 29(9): 71-73,78.
ZHANG Ben-qun. Information Security Risk Assessment Method of E-Government System Based on Danger Theory[J]. Microelectronics & Computer, 2012, 29(9): 71-73,78.
Citation: ZHANG Ben-qun. Information Security Risk Assessment Method of E-Government System Based on Danger Theory[J]. Microelectronics & Computer, 2012, 29(9): 71-73,78.

基于危险理论的电子政务系统信息安全风险评估

Information Security Risk Assessment Method of E-Government System Based on Danger Theory

  • 摘要: 为了电子政务系统安全信息评估精度,依据资产、脆弱性、威胁等风险评估基本要素,提出一种基于危险理论的电子政务系统信息安全风险评估方法.该方法以威胁为核心,通过威胁分析、梯形模糊数、层次分析法,结合多属性决策理论得到威胁发生的概率、后果属性以及属性值,得到电子政务系统信息安全威胁指数,最后利用威胁指数对风险进行排序,得到系统信息安全的风险等级.仿真结果表明,该方法能够很好地量化电子政务系统信息安全风险指标,有效地提高了风险评估准确性,是一种有效的电子政务系统信息安全评估方法.

     

    Abstract: On the basis of asset, threat, vulnerability and risk assessment of basic elements, based on the threat of trapezoidal fuzzy analytic hierarchy process in e-government information security risk assessment method.The method for threat as the core, through the analysis of threats, trapezoidal fuzzy number, analytic hierarchy process, combined with the multiple attribute decision making theory to get the probability of occurrence of the consequences of threat, attribute and attribute value, get of e-government information systems security threat index, finally uses the threat index on the risk sort, get system information security risk rating.The simulation results show that, the method is able to quantify the e-government system information security risk index, to effectively improve the accuracy of risk assessment, is an effective evaluation method of information security in electronic government system.

     

/

返回文章
返回