Security risk analysis and management

被引:2
|
作者
Anton, Nicolae [1 ]
Nedelcu, Anisor [1 ]
机构
[1] Transilvania Univ Brasov, Fac Technol Engn & Ind Management, B Dul Eroilor 29, Brasov, Romania
关键词
D O I
10.1051/matecconf/201817808015
中图分类号
TE [石油、天然气工业]; TK [能源与动力工程];
学科分类号
0807 ; 0820 ;
摘要
The management system of informational security is a part of the management system of an organization, that approaches the management of risk from the point of view of the involved information, approach that is used in order to set, to implement, to function, to monitor, to revise, to maintain and to improve the informational security at the organizational level, referring to the progress of the processes required by the management of risk in order to guarantee the security of the information. The appreciation of the efficiency of the security system represents a difficult problem and it contains many elements of subjectiveness, because the analysis of the security risks of information implies using some interviewing techniques based on questionnaires provided by experts in security, that in most of the cases come from outside the organization. This study does not analyse the risk concept, it focuses more on the analysis and the risk management on the practical part using AHP method. Managing the risk and the security requirements are connected by a set of practices and management tools generally used in order to manage the security risk of information. It is essential that the tool and the model used should reflect the objective needs of the organization from the point of view of the management of risk.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] Enterprise Risk Management and Information Systems Security Risk
    Olson, David L.
    Wu, Desheng
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON RISK MANAGEMENT & GLOBAL E-BUSINESS, VOLS I AND II, 2009, : 1 - 5
  • [42] Information security risk assessment model for risk management
    Wawrzyniak, Dariusz
    TRUST, PRIVACY, AND SECURITY IN DIGITAL BUSINESS, PROCEEDINGS, 2006, 4083 : 21 - 30
  • [43] Monitoring the Effectiveness of Security Countermeasures in a Security Risk Management Model
    Rjaibi, Neila
    Rabai, Latifa Ben Arfa
    SOFTWARE ENGINEERING IN INTELLIGENT SYSTEMS (CSOC2015), VOL 3, 2015, 349 : 327 - 337
  • [44] A DSS for information security analysis: Computer support in a company's risk management
    Finne, T
    INFORMATION INTELLIGENCE AND SYSTEMS, VOLS 1-4, 1996, : 193 - 198
  • [45] E-commerce Security Risk Analysis and Management Strategies of Commercial Banks
    Li Bo
    Xu Congwei
    2009 INTERNATIONAL FORUM ON INFORMATION TECHNOLOGY AND APPLICATIONS, VOL 1, PROCEEDINGS, 2009, : 423 - 425
  • [46] Automatic security management of smart infrastructures using attack graph and risk analysis
    Ivanov, Denis
    Kalinin, Maxim
    Krudyshev, Vasiliy
    Orel, Evgeniy
    PROCEEDINGS OF THE 2020 FOURTH WORLD CONFERENCE ON SMART TRENDS IN SYSTEMS, SECURITY AND SUSTAINABILITY (WORLDS4 2020), 2020, : 295 - 300
  • [47] RAMEX - A PROTOTYPE EXPERT-SYSTEM FOR COMPUTER SECURITY RISK ANALYSIS AND MANAGEMENT
    KAILAY, MP
    JARRATT, P
    COMPUTERS & SECURITY, 1995, 14 (05) : 449 - 463
  • [48] Security risk management in Norwegian aviation meets nordic traditions of risk management
    Engen, O. A.
    ADVANCES IN SAFETY, RELIABILITY AND RISK MANAGEMENT, 2012, : 1776 - 1782
  • [49] Systems analysis of security management
    Sienkiewicz, Piotr
    SCIENTIFIC JOURNALS OF THE MARITIME UNIVERSITY OF SZCZECIN-ZESZYTY NAUKOWE AKADEMII MORSKIEJ W SZCZECINIE, 2010, 24 (96): : 93 - 99
  • [50] Security modelling for risk analysis
    Kwok, LF
    Longley, D
    SECURITY AND PROTECTION IN INFORMATION PROCESSING SYSTEMS, 2004, 147 : 29 - 45