Method and device for conducting security identification on information system
An information system and security technology, applied in the field of security identification of information systems, can solve the problem that threat identification is difficult to meet the security identification requirements of information systems
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Publication Date
- 2010-03-17
- Estimated Expiration
- Not applicable · inactive patent
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention relates to the technical field of security information, in particular to a method and device for security identification of an information system. Background technique
[0002] Information system security identification refers to the process of identifying security attributes such as confidentiality, integrity and availability of information systems and information processed, transmitted and stored according to relevant information security technology and management standards. The most important step in the process of security identification is how to identify threats and quantify the possibility of threat occurrence. In the prior art, when threat identification is performed, it mainly relies on the security evaluation personnel of the information system to make judgments based on technical experience, scan the information system for vulnerabilities and obtain the vulnerability information of the information system, and determine the thre...
Examples
no. 1 example
[0063] see figure 1 , which is a flow chart of the first embodiment of the method for security identification of an information system in the present invention:
[0064] Step 101: Determine the target information system.
[0065] Step 102: Obtain the security attribute values of each asset in the target information system and the quantified value of the corresponding threat category according to the result of security threat modeling of the target information system.
[0066] Step 103: Calculate the security information value of each asset in the target information system according to the quantified value of the threat category.
[0067] Step 104: Obtain the security information value of the target information system according to the security information value of each asset and the weight value of each asset in the target information system.
[0068] Step 105: Search the preset security level list according to the security information value of the target information system...