Information asset risk assessment method and device

By combining information asset characteristic data and risk calculation models with machine learning algorithms, the risk assessment problem caused by the complexity of information systems is solved, and the accuracy and intelligent disposal of information asset risk assessment are achieved.

CN115392719BActive Publication Date: 2025-09-26INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211031776.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-26
Publication Date
2025-09-26
Estimated Expiration
2042-08-26

AI Technical Summary

Technical Problem

The complexity and openness of information systems and networks in existing technologies have led to increased concealment and complexity in information asset risk assessment, making it difficult to accurately identify and assess security risks.

Method used

The information asset value is determined through the company's information asset characteristic data and information asset value calculation model; the asset risk value is determined based on the risk impact level, risk possibility and risk value calculation model; and the risk level and disposal measures are determined based on the information asset category, using machine learning algorithms and Pearson algorithms to improve assessment accuracy.

Benefits of technology

It effectively improves the accuracy of information asset risk assessment, and can intelligently identify risks and provide corresponding disposal measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115392719B_ABST
    Figure CN115392719B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides an information asset risk assessment method and device, which can be used in the financial field. The method includes: determining the information asset value of an enterprise based on the enterprise's information asset characteristic data and an information asset value calculation model; determining the asset risk value of the enterprise based on the information asset value, the corresponding risk impact level, the possibility of risk occurrence, and the risk value calculation model; determining the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value, and the information asset category; the present application can effectively improve the accuracy of information asset risk assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of mathematical modeling and can also be used in the financial field. Specifically, it relates to an information asset risk assessment method and device. Background Art

[0002] With the rapid development and application of the Internet and information technology, enterprises are increasingly dependent on information systems. The number of information assets of enterprises will increase and the types will become more and more diverse. All walks of life are increasingly dependent on information technology. The use of risk assessment to identify security risks and solve information security problems has been widely recognized and applied.

[0003] The inventors found that due to the complexity and openness of information systems and networks themselves, the risks they face are also more hidden and complex, which has made information technology risk management a hot issue in recent years. Summary of the Invention

[0004] In response to the problems in the prior art, the present application provides an information asset risk assessment method and device, which can effectively improve the accuracy of information asset risk assessment.

[0005] In order to solve at least one of the above problems, the present application provides the following technical solutions:

[0006] In a first aspect, the present application provides an information asset risk assessment method, comprising:

[0007] Determining the information asset value of the enterprise based on the enterprise's information asset characteristic data and an information asset value calculation model;

[0008] Determining the asset risk value of the enterprise based on the information asset value, the corresponding risk impact level, the risk occurrence probability, and the risk value calculation model;

[0009] The information asset risk level and corresponding disposal measures are determined based on the information asset value, the asset risk value and the information asset category.

[0010] Furthermore, determining the information asset value of the enterprise based on the enterprise's information asset characteristic data and the information asset value calculation model includes:

[0011] The corresponding confidentiality characteristics are calculated based on the weighted data of the enterprise's information asset category and function data;

[0012] Obtaining corresponding integrity characteristics by weighted calculation based on the importance data of the information assets of the enterprise;

[0013] Obtaining corresponding availability characteristics by weighted calculation based on the enterprise's information asset service continuity data;

[0014] The confidentiality feature, the integrity feature, and the availability feature are input into a preset information asset value calculation model to determine the information asset value of the enterprise.

[0015] Furthermore, determining the asset risk value of the enterprise based on the information asset value, the corresponding risk impact level, the risk occurrence probability, and the risk value calculation model includes:

[0016] Determine the characteristic vector value of the information asset value, risk impact degree and risk occurrence possibility according to a preset indicator scoring algorithm;

[0017] The similarity between the characteristic vectors is determined according to a preset Pearson algorithm, and the asset risk value of the enterprise is determined according to the similarity calculation result.

[0018] Furthermore, determining the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value, and the information asset category includes:

[0019] Establishing a feature vector model corresponding to the information asset value, the asset risk value, and the information asset category;

[0020] The information asset risk level and corresponding disposal measures are determined based on the similarity between each of the feature vector models and the preset reference vector.

[0021] In a second aspect, the present application provides an information asset risk assessment device, comprising:

[0022] An information asset value determination module, configured to determine the information asset value of an enterprise based on the enterprise's information asset characteristic data and an information asset value calculation model;

[0023] An asset risk value determination module is used to determine the asset risk value of the enterprise based on the information asset value, the corresponding risk impact level, the risk occurrence probability and the risk value calculation model;

[0024] The risk determination module is used to determine the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value and the information asset category.

[0025] Furthermore, the information asset value determination module includes:

[0026] A confidentiality feature determination unit, configured to obtain a corresponding confidentiality feature by weighted calculation based on the enterprise's information asset category data and function data;

[0027] An integrity feature determination unit, configured to obtain a corresponding integrity feature by weighted calculation based on the importance data of the information assets of the enterprise;

[0028] an availability feature determination unit, configured to obtain corresponding availability features by weighted calculation based on the information asset service continuity data of the enterprise;

[0029] The risk level determination unit is configured to input the confidentiality feature, the integrity feature, and the availability feature into a preset information asset value calculation model to determine the information asset value of the enterprise.

[0030] Furthermore, the asset risk value determination module includes:

[0031] A feature scoring unit, configured to determine the feature vector values ​​of the information asset value, risk impact level, and risk occurrence probability according to a preset indicator scoring algorithm;

[0032] The risk value calculation unit is used to determine the similarity between each feature vector according to a preset Pearson algorithm, and determine the asset risk value of the enterprise according to the similarity calculation result.

[0033] Furthermore, the risk determination module includes:

[0034] a risk factor determination unit, configured to establish a feature vector model corresponding to the information asset value, the asset risk value, and the information asset category;

[0035] The similarity calculation unit is used to determine the information asset risk level and the corresponding disposal measures according to the similarity between each of the feature vector models and the preset reference vector.

[0036] In a third aspect, the present application provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the information asset risk assessment method when executing the program.

[0037] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the information asset risk assessment method when executed by a processor.

[0038] In a fifth aspect, the present application provides a computer program product, comprising a computer program / instruction, which implements the steps of the information asset risk assessment method when executed by a processor.

[0039] It can be seen from the above technical solution that the present application provides an information asset risk assessment method and device, which determines the information asset value of an enterprise through the enterprise's information asset characteristic data and information asset value calculation model; determines the asset risk value of the enterprise based on the information asset value, the corresponding risk impact level, the possibility of risk occurrence and the risk value calculation model; determines the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value and the information asset category, thereby effectively improving the accuracy of information asset risk assessment. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0041] Figure 1 This is one of the flow charts of the information asset risk assessment method in the embodiment of the present application;

[0042] Figure 2 This is a second flow chart of the information asset risk assessment method in an embodiment of the present application;

[0043] Figure 3 This is the third flow chart of the information asset risk assessment method in the embodiment of the present application;

[0044] Figure 4 This is a fourth flow chart of the information asset risk assessment method according to an embodiment of the present application;

[0045] Figure 5 This is one of the structural diagrams of the information asset risk assessment device in an embodiment of the present application;

[0046] Figure 6 This is the second structural diagram of the information asset risk assessment device in the embodiment of the present application;

[0047] Figure 7 This is the third structural diagram of the information asset risk assessment device in the embodiment of the present application;

[0048] Figure 8 This is the fourth structural diagram of the information asset risk assessment device in the embodiment of the present application;

[0049] Figure 9 Schematic diagram of the structure of the electronic device in the embodiment of the present application. DETAILED DESCRIPTION

[0050] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0051] The acquisition, storage, use, and processing of data in this application's technical solution comply with relevant national laws and regulations.

[0052] Taking into account the complexity and openness of information systems and networks in the existing technology, the risks they face are also more hidden and complex. This application provides an information asset risk assessment method and device, which determines the information asset value of an enterprise through the enterprise's information asset characteristic data and an information asset value calculation model; determines the asset risk value of the enterprise based on the information asset value, the corresponding risk impact level, the possibility of risk occurrence and the risk value calculation model; determines the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value and the information asset category, thereby effectively improving the accuracy of information asset risk assessment.

[0053] In order to effectively improve the accuracy of information asset risk assessment, this application provides an embodiment of an information asset risk assessment method, see Figure 1 The information asset risk assessment method specifically includes the following contents:

[0054] Step S101: Determine the information asset value of the enterprise based on the enterprise's information asset characteristic data and the information asset value calculation model.

[0055] Optionally, this application may establish separate evaluation indicators, such as confidentiality, integrity, availability, deployment environment, and disaster recovery level. A computer program may perform data analysis, create scoring rules, and automatically determine scores for each indicator within a range of {1, 2, 3, 4, 5} to obtain the indicator scores. For example, the value of "confidentiality" is calculated by weighting the information asset's category and function. The value of "integrity" is calculated by weighting the information asset's importance. The value of "availability" is calculated by weighting the information asset's service continuity.

[0056] Specifically, by establishing a calculation model for information asset value, inputting confidentiality, integrity, availability, deployment environment, and disaster recovery level score data, the information asset value is output with the help of the calculation model, and the information asset value is obtained by calling the machine learning algorithm through model calculation, and the relevant information data is stored in the enterprise information asset risk assessment database.

[0057] Optionally, risk assessment identifies three key elements: information assets, vulnerabilities, and threats. This process then determines evaluation indicators, assigns them a value and grading, and ultimately determines the risk value. Information assets are valuable information or resources for the enterprise and are protected by security policies. Threats are potential causes of incidents that could harm assets or organizations. Vulnerabilities are weaknesses and hidden dangers within an asset or asset group that can be exploited by threats. This article analyzes and models evaluation indicators such as confidentiality, integrity, availability, deployment environment, and disaster recovery level to calculate the asset value of information assets.

[0058] In one example, the value of assets in information security risk assessment is not measured by their economic value. Instead, the information asset value is calculated by assigning grades to the evaluation elements. The calculation model for the information asset value is as follows:

[0059] AssetValue=10*ROUND1{Log2[(2 C +2 I +2 A +2 E +2 Z ) / 5]};

[0060] Among them, AssetValue represents the information asset value;

[0061] C represents the confidentiality value, which ranges from {1, 2, 3, 4, 5};

[0062] I represents the integrity assignment, and the value range is {1, 2, 3, 4, 5};

[0063] A represents the availability value, which ranges from {1, 2, 3, 4, 5};

[0064] E represents the deployment environment, and its value range is {1, 2, 3, 4, 5};

[0065] Z represents the disaster recovery level, and its value range is {1, 2, 3, 4, 5}.

[0066] Use existing data to establish training sets and test sets, train and test the new model, and gradually optimize and improve the model precision and accuracy.

[0067] With the help of the new model, functions such as online information asset value calculation, risk value calculation, and online information asset risk assessment are provided.

[0068] Step S102: Determine the asset risk value of the enterprise according to the information asset value, the corresponding risk impact level, the risk occurrence possibility and the risk value calculation model.

[0069] Optionally, this application can establish risk value calculation evaluation indicators, such as: asset value, risk impact level, and risk occurrence possibility; use a computer program to call a machine learning algorithm to score each indicator separately, with a value range of {1, 2, 3, 4, 5}; obtain the indicator score, and calculate the information asset risk value through the model; and store the relevant information data in the enterprise information asset risk assessment database.

[0070] In one example, the risk value intelligent calculation model algorithm first establishes reference standard asset values, risk impact levels, and risk occurrence probability vector data with risk values ​​of 1, 2, 3, 4, and 5, respectively: "Risk value 1" feature vector {a1, b1, c1}, "Risk value 2" feature vector {a2, b2, c2}, "Risk value 3" feature vector {a3, b3, c3}, "Risk value 4" feature vector {a4, b4, c4}, "Risk value 5" feature vector {a5, b5, c5}. For a certain information asset, the similarity between the feature vectors is calculated using the Pearson model based on the asset value, risk impact level, and risk occurrence probability feature vectors {i1, i2, i3}.

[0071]

[0072] According to the similarity calculation results, the one with the highest similarity of Max(P1, P2, P3, P4, P5) is selected and assigned the corresponding risk value.

[0073] Step S103: Determine the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value, and the information asset category.

[0074] Optionally, this application can use machine learning technology to improve the intelligence level of risk assessment, and use the random forest algorithm to realize intelligent assessment and analysis of the asset value and risk value of information assets through the management platform, model previous enterprise information asset risk assessment data, and provide recommended risk assessment and disposal intelligent recommendation plans based on the information asset situation.

[0075] Specifically, this application can analyze the existing risk assessment and disposal data through cluster analysis and similarity calculation, provide risk assessment and disposal references for similar information assets and information assets with risk values ​​in the same range, and provide intelligent recommendations for risk assessment and disposal suggestions such as "threats" and "weak points".

[0076] Specifically, the present application can respectively establish information asset category, information asset value, and information asset risk value N as feature vector models, and use existing stock risk assessment "threats", "weak points" and other risk assessment and disposal data as reference vectors. Subsequently, by calculating the similarity between a certain information asset feature vector and the reference feature vector, intelligently recommend information asset risk assessment and disposal "threats" and "weak points" recommended data.

[0077] In the model where information asset category, information asset value, and information asset risk value N are feature vectors, for example, the reference feature vector of the "threat" of "software and hardware failure" is {X1, X2, X3}, and the feature vector of a certain information asset is {Y1, Y2, Y3}, by calculating the similarity P of the two feature vectors X and Y, if P is greater than a certain threshold, the "threat" of "software and hardware failure" is intelligently recommended for the information asset Y, thereby realizing intelligent recommendation of information asset risk assessment and disposal methods.

[0078]

[0079] From the above description, it can be seen that the information asset risk assessment method provided in the embodiment of the present application can determine the information asset value of the enterprise through the enterprise's information asset characteristic data and the information asset value calculation model; determine the asset risk value of the enterprise based on the information asset value, the corresponding risk impact level, the possibility of risk occurrence and the risk value calculation model; determine the information asset risk level and the corresponding disposal measures based on the information asset value, the asset risk value and the information asset category, thereby effectively improving the accuracy of information asset risk assessment.

[0080] In order to accurately determine the information asset value of an enterprise, in one embodiment of the information asset risk assessment method of the present application, see Figure 2 , the above step S101 may further specifically include the following contents:

[0081] Step S201: derive corresponding confidentiality characteristics based on weighted calculation of the enterprise's information asset category data and function data.

[0082] Step S202: Obtain corresponding integrity characteristics by weighted calculation based on the importance data of the enterprise's information assets.

[0083] Step S203: Obtain corresponding availability characteristics through weighted calculation based on the enterprise's information asset service continuity data.

[0084] Step S204: inputting the confidentiality feature, the integrity feature, and the availability feature into a preset information asset value calculation model to determine the information asset value of the enterprise.

[0085] Optionally, this application may establish separate evaluation indicators, such as confidentiality, integrity, availability, deployment environment, and disaster recovery level. A computer program may perform data analysis, create scoring rules, and automatically determine scores for each indicator within a range of {1, 2, 3, 4, 5} to obtain the indicator scores. For example, the value of "confidentiality" is calculated by weighting the information asset's category and function. The value of "integrity" is calculated by weighting the information asset's importance. The value of "availability" is calculated by weighting the information asset's service continuity.

[0086] In order to accurately determine the asset risk value of an enterprise, in one embodiment of the information asset risk assessment method of this application, see Figure 3 , the above step S102 may further specifically include the following contents:

[0087] Step S301: Determine the characteristic vector values ​​of the information asset value, risk impact level, and risk occurrence possibility according to a preset indicator scoring algorithm.

[0088] Step S302: Determine the similarity between the eigenvectors according to a preset Pearson algorithm, and determine the asset risk value of the enterprise according to the similarity calculation result.

[0089] In one example, the risk value intelligent calculation model algorithm first establishes reference standard asset values, risk impact levels, and risk occurrence probability vector data with risk values ​​of 1, 2, 3, 4, and 5, respectively: "Risk value 1" feature vector {a1, b1, c1}, "Risk value 2" feature vector {a2, b2, c2}, "Risk value 3" feature vector {a3, b3, c3}, "Risk value 4" feature vector {a4, b4, c4}, "Risk value 5" feature vector {a5, b5, c5}. For a certain information asset, the similarity between the feature vectors is calculated using the Pearson model based on the asset value, risk impact level, and risk occurrence probability feature vectors {i1, i2, i3}.

[0090] According to the similarity calculation results, the one with the highest similarity of Max(P1, P2, P3, P4, P5) is selected and assigned the corresponding risk value.

[0091] In order to accurately determine the information asset risk level, in one embodiment of the information asset risk assessment method of the present application, see Figure 4 , the above step S103 may further specifically include the following contents:

[0092] Step S401: establishing a feature vector model corresponding to the information asset value, the asset risk value, and the information asset category.

[0093] Step S402: Determine the information asset risk level and corresponding disposal measures based on the similarity between each of the feature vector models and the preset reference vector.

[0094] Specifically, the present application can respectively establish information asset category, information asset value, and information asset risk value N as feature vector models, and use existing stock risk assessment "threats", "weak points" and other risk assessment and disposal data as reference vectors. Subsequently, by calculating the similarity between a certain information asset feature vector and the reference feature vector, intelligently recommend information asset risk assessment and disposal "threats" and "weak points" recommended data.

[0095] In the model where information asset category, information asset value, and information asset risk value N are feature vectors, for example, the reference feature vector of the "threat" of "software and hardware failure" is {X1, X2, X3}, and the feature vector of a certain information asset is {Y1, Y2, Y3}, by calculating the similarity P of the two feature vectors X and Y, if P is greater than a certain threshold, the "threat" of "software and hardware failure" is intelligently recommended for the information asset Y, thereby realizing intelligent recommendation of information asset risk assessment and disposal methods.

[0096] In order to effectively improve the accuracy of information asset risk assessment, the present application provides an embodiment of an information asset risk assessment device for implementing all or part of the information asset risk assessment method. Figure 5 The information asset risk assessment device specifically includes the following contents:

[0097] The information asset value determination module 10 is used to determine the information asset value of the enterprise based on the enterprise's information asset characteristic data and the information asset value calculation model.

[0098] The asset risk value determination module 20 is used to determine the asset risk value of the enterprise according to the information asset value, the corresponding risk impact level, the probability of risk occurrence and the risk value calculation model.

[0099] The risk determination module 30 is configured to determine the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value, and the information asset category.

[0100] From the above description, it can be seen that the information asset risk assessment device provided in the embodiment of the present application can determine the information asset value of the enterprise through the information asset characteristic data and information asset value calculation model of the enterprise; determine the asset risk value of the enterprise according to the information asset value, the corresponding risk impact level, the possibility of risk occurrence and the risk value calculation model; determine the information asset risk level and the corresponding disposal measures according to the information asset value, the asset risk value and the information asset category, thereby effectively improving the accuracy of information asset risk assessment.

[0101] In order to accurately determine the information asset value of an enterprise, in one embodiment of the information asset risk assessment device of the present application, see Figure 6 , the information asset value determination module 10 includes:

[0102] The confidentiality feature determination unit 11 is configured to obtain a corresponding confidentiality feature by weighted calculation based on the enterprise's information asset category data and function data.

[0103] The integrity feature determination unit 12 is configured to obtain a corresponding integrity feature by weighted calculation based on the importance data of the information assets of the enterprise.

[0104] The availability characteristic determination unit 13 is configured to obtain corresponding availability characteristics by weighted calculation based on the information asset service continuity data of the enterprise.

[0105] The risk level determination unit 14 is configured to input the confidentiality feature, the integrity feature, and the availability feature into a preset information asset value calculation model to determine the information asset value of the enterprise.

[0106] In order to accurately determine the asset risk value of an enterprise, in one embodiment of the information asset risk assessment device of the present application, see Figure 7 , the asset risk value determination module 20 includes:

[0107] The feature scoring unit 21 is used to determine the feature vector values ​​of the information asset value, risk impact degree and risk occurrence possibility according to a preset indicator scoring algorithm.

[0108] The risk value calculation unit 22 is used to determine the similarity between the feature vectors according to a preset Pearson algorithm, and determine the asset risk value of the enterprise according to the similarity calculation result.

[0109] In order to accurately determine the information asset risk level, in one embodiment of the information asset risk assessment device of the present application, see Figure 8 , the risk determination module 30 includes:

[0110] The risk factor determination unit 31 is configured to establish a feature vector model corresponding to the information asset value, the asset risk value, and the information asset category.

[0111] The similarity calculation unit 32 is used to determine the information asset risk level and the corresponding disposal measures according to the similarity between each of the feature vector models and the preset reference vector.

[0112] From a hardware perspective, in order to effectively improve the accuracy of information asset risk assessment, this application provides an embodiment of an electronic device for implementing all or part of the information asset risk assessment method. The electronic device specifically includes the following:

[0113] A processor, a memory, a communications interface, and a bus; wherein the processor, memory, and communications interface communicate with each other via the bus; the communications interface is used to transmit information between the information asset risk assessment device and related devices such as core business systems, user terminals, and related databases; the logic controller can be a desktop computer, a tablet computer, a mobile terminal, etc., but this embodiment is not limited thereto. In this embodiment, the logic controller can be implemented with reference to the embodiments of the information asset risk assessment method and the embodiments of the information asset risk assessment device in the embodiments, the contents of which are incorporated herein and repeated parts are not repeated.

[0114] It is understandable that the user terminal may include a smart phone, a tablet electronic device, a network set-top box, a portable computer, a desktop computer, a personal digital assistant (PDA), a vehicle-mounted device, a smart wearable device, etc. Among them, the smart wearable device may include smart glasses, a smart watch, a smart bracelet, etc.

[0115] In practical applications, portions of the information asset risk assessment method may be executed on the electronic device as described above, or all operations may be performed on the client device. The specific method may be selected based on the processing capabilities of the client device and the limitations of the user's usage scenario. This application does not impose any restrictions on this. If all operations are performed on the client device, the client device may also include a processor.

[0116] The client device may include a communication module (i.e., a communication unit) that can establish a communication connection with a remote server to implement data transmission with the server. The server may include a server on the task scheduling center side, and in other implementation scenarios, may also include a server on an intermediate platform, such as a server on a third-party server platform that has a communication link with the task scheduling center server. The server may include a single computer device, a server cluster consisting of multiple servers, or a server structure of a distributed device.

[0117] Figure 9 Schematic block diagram of the system structure of the electronic device 9600 according to an embodiment of the present application. Figure 9As shown, the electronic device 9600 may include a central processing unit 9100 and a memory 9140; the memory 9140 is coupled to the central processing unit 9100. It is worth noting that the Figure 9 is exemplary; other types of structures may also be used to supplement or replace this structure to implement telecommunication functions or other functions.

[0118] In one embodiment, the information asset risk assessment method function may be integrated into the central processing unit 9100 .

[0119] The central processing unit 9100 may be configured to perform the following control:

[0120] Step S101: Determine the information asset value of the enterprise based on the enterprise's information asset characteristic data and the information asset value calculation model.

[0121] Step S102: Determine the asset risk value of the enterprise according to the information asset value, the corresponding risk impact level, the risk occurrence possibility and the risk value calculation model.

[0122] Step S103: Determine the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value, and the information asset category.

[0123] From the above description, it can be seen that the electronic device provided in the embodiment of the present application determines the information asset value of the enterprise through the information asset characteristic data and information asset value calculation model of the enterprise; determines the asset risk value of the enterprise according to the information asset value, the corresponding risk impact level, the possibility of risk occurrence and the risk value calculation model; determines the information asset risk level and the corresponding disposal measures according to the information asset value, the asset risk value and the information asset category, thereby effectively improving the accuracy of information asset risk assessment.

[0124] In another embodiment, the information asset risk assessment device can be configured separately from the central processor 9100. For example, the information asset risk assessment device can be configured as a chip connected to the central processor 9100, and the information asset risk assessment method function can be implemented under the control of the central processor.

[0125] like Figure 9 As shown, the electronic device 9600 may further include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It is worth noting that the electronic device 9600 does not necessarily have to include Figure 9 In addition, the electronic device 9600 may also include all components shown in Figure 9 For components not shown, reference may be made to the prior art.

[0126] like Figure 9 As shown, the central processing unit 9100 is sometimes also referred to as a controller or operation control, and may include a microprocessor or other processor device and / or logic device. The central processing unit 9100 receives input and controls the operation of various components of the electronic device 9600.

[0127] Memory 9140 can be, for example, one or more of a cache, flash memory, hard drive, removable media, volatile memory, non-volatile memory, or other suitable devices. It can store the aforementioned failure-related information and also store programs that execute the relevant information. The CPU 9100 can execute the programs stored in memory 9140 to implement information storage or processing.

[0128] The input unit 9120 provides input to the central processing unit 9100. The input unit 9120 may be, for example, a keypad or touch input device. The power supply 9170 is used to provide power to the electronic device 9600. The display 9160 is used to display objects such as images and text. The display may be, for example, an LCD display, but is not limited thereto.

[0129] The memory 9140 may be a solid-state memory, such as a read-only memory (ROM), a random access memory (RAM), or a SIM card. Alternatively, it may be a memory that retains information even when power is off, can be selectively erased, and is provided with more data. Examples of such memory are sometimes referred to as EPROMs. The memory 9140 may also be some other type of device. The memory 9140 includes a buffer memory 9141 (sometimes referred to as a buffer). The memory 9140 may include an application / function storage unit 9142 for storing application programs and function programs or processes for executing the operation of the electronic device 9600 by the central processing unit 9100.

[0130] The memory 9140 may also include a data storage unit 9143 for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 may include various driver programs for communication functions of the electronic device and / or for executing other functions of the electronic device (such as messaging applications, address book applications, etc.).

[0131] The communication module 9110 is a transmitter / receiver 9110 that transmits and receives signals via an antenna 9111. The communication module (transmitter / receiver) 9110 is coupled to the central processor 9100 to provide input signals and receive output signals, which may be the same as in a conventional mobile communication terminal.

[0132] Based on different communication technologies, multiple communication modules 9110 can be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module. The communication module (transmitter / receiver) 9110 is also coupled to a speaker 9131 and a microphone 9132 via an audio processor 9130 to provide audio output via the speaker 9131 and receive audio input from the microphone 9132, thereby implementing common telecommunication functions. The audio processor 9130 may include any suitable buffer, decoder, amplifier, etc. Furthermore, the audio processor 9130 is also coupled to the central processing unit 9100, enabling local recording via the microphone 9132 and playback of stored audio via the speaker 9131.

[0133] Embodiments of the present application also provide a computer-readable storage medium capable of implementing all steps of the information asset risk assessment method in the above-mentioned embodiment, where the execution subject is a server or a client. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the computer program implements all steps of the information asset risk assessment method in the above-mentioned embodiment, where the execution subject is a server or a client. For example, when the processor executes the computer program, the following steps are implemented:

[0134] Step S101: Determine the information asset value of the enterprise based on the enterprise's information asset characteristic data and the information asset value calculation model.

[0135] Step S102: Determine the asset risk value of the enterprise according to the information asset value, the corresponding risk impact level, the risk occurrence possibility and the risk value calculation model.

[0136] Step S103: Determine the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value, and the information asset category.

[0137] From the above description, it can be seen that the computer-readable storage medium provided in the embodiment of the present application determines the information asset value of the enterprise through the information asset characteristic data and information asset value calculation model of the enterprise; determines the asset risk value of the enterprise according to the information asset value, the corresponding risk impact level, the possibility of risk occurrence and the risk value calculation model; determines the information asset risk level and the corresponding disposal measures according to the information asset value, the asset risk value and the information asset category, thereby effectively improving the accuracy of information asset risk assessment.

[0138] The present application also provides a computer program product capable of implementing all steps of the information asset risk assessment method described in the above embodiment, where the execution subject is a server or a client. When the computer program / instructions are executed by a processor, the steps of the information asset risk assessment method are implemented. For example, the computer program / instructions implement the following steps:

[0139] Step S101: Determine the information asset value of the enterprise based on the enterprise's information asset characteristic data and the information asset value calculation model.

[0140] Step S102: Determine the asset risk value of the enterprise according to the information asset value, the corresponding risk impact level, the risk occurrence possibility and the risk value calculation model.

[0141] Step S103: Determine the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value, and the information asset category.

[0142] From the above description, it can be seen that the computer program product provided in the embodiment of the present application determines the information asset value of the enterprise through the enterprise's information asset characteristic data and the information asset value calculation model; determines the asset risk value of the enterprise based on the information asset value, the corresponding risk impact level, the possibility of risk occurrence and the risk value calculation model; determines the information asset risk level and the corresponding disposal measures based on the information asset value, the asset risk value and the information asset category, thereby effectively improving the accuracy of information asset risk assessment.

[0143] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatus, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0144] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (apparatus), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as a combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1A device that provides the functions specified in a block or multiple blocks.

[0145] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0146] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0147] Specific embodiments are used in the present invention to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.

Claims

1. A method for assessing information asset risk, characterized in that: The method comprises: Determining the information asset value of the enterprise based on the enterprise's information asset characteristic data and an information asset value calculation model; Determining the asset risk value of the enterprise based on the information asset value, the corresponding risk impact level, the risk occurrence probability, and the risk value calculation model; Determining the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value, and the information asset category; The step of determining the enterprise's asset risk value based on the information asset value, the corresponding risk impact level, the risk occurrence probability, and the risk value calculation model includes: Establish reference standard information asset value, risk impact level, and risk occurrence probability vector data; Determine the characteristic vector value of the information asset value, risk impact degree and risk occurrence possibility according to a preset indicator scoring algorithm; Determine the similarity between the reference standard information asset value, risk impact level, risk occurrence possibility vector data and the feature vector value according to a preset Pearson algorithm, and determine the asset risk value of the enterprise according to the similarity calculation result; The step of determining the information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value, and the information asset category includes: Establishing a feature vector model corresponding to the information asset value, the asset risk value, and the information asset category; Determining the information asset risk level and corresponding disposal measures based on the similarity between each of the feature vector models and a preset reference vector; The information asset value calculation model is as follows: AssetValue=10*ROUND1{log2[(2 C +2 I +2 A +2 E +2 Z ) / 5]}; Among them, AssetValue represents the information asset value; C represents the confidentiality value, which ranges from {1, 2, 3, 4, 5}; I represents the integrity assignment, and the value range is {1, 2, 3, 4, 5}; A represents the availability value, which ranges from {1, 2, 3, 4, 5}; E represents the deployment environment, and its value range is {1, 2, 3, 4, 5}; Z represents the disaster recovery level, and its value range is {1, 2, 3, 4, 5}.

2. The information asset risk assessment method according to claim 1, characterized in that: Determining the information asset value of the enterprise based on the enterprise's information asset characteristic data and the information asset value calculation model includes: The corresponding confidentiality value is obtained by weighted calculation based on the enterprise's information asset category data and functional data; Obtaining a corresponding integrity value by weighted calculation based on the importance data of the information assets of the enterprise; Obtaining a corresponding availability value by weighted calculation based on the enterprise's information asset service continuity data; The confidentiality assignment, the integrity assignment, the availability assignment, the deployment environment, and the disaster recovery level are input into a preset information asset value calculation model to determine the information asset value of the enterprise.

3. An information asset risk assessment device, characterized in that: include: An information asset value determination module, configured to determine the information asset value of an enterprise based on the enterprise's information asset characteristic data and an information asset value calculation model; An asset risk value determination module is used to determine the asset risk value of the enterprise based on the information asset value, the corresponding risk impact level, the risk occurrence probability and the risk value calculation model; A risk determination module, configured to determine an information asset risk level and corresponding disposal measures based on the information asset value, the asset risk value, and the information asset category; The asset risk value determination module includes: Reference data establishment module, used to establish reference standard information asset value, risk impact level, and risk occurrence probability vector data; A feature scoring unit, configured to determine the feature vector values ​​of the information asset value, risk impact level, and risk occurrence probability according to a preset indicator scoring algorithm; a risk value calculation unit, configured to determine the similarity between the reference standard information asset value, risk impact degree, risk occurrence possibility vector data and the feature vector value according to a preset Pearson algorithm, and determine the asset risk value of the enterprise according to the similarity calculation result; Wherein, the risk determination module includes: a risk factor determination unit, configured to establish a feature vector model corresponding to the information asset value, the asset risk value, and the information asset category; A similarity calculation unit, configured to determine the information asset risk level and corresponding disposal measures based on the similarity between each of the feature vector models and a preset reference vector; The information asset value calculation model is as follows: AssetValue=10*ROUND1{log2[(2 C +2 I +2 A +2 E +2 Z ) / 5]}; Among them, AssetValue represents the information asset value; C represents the confidentiality value, which ranges from {1, 2, 3, 4, 5}; I represents the integrity assignment, and the value range is {1, 2, 3, 4, 5}; A represents the availability value, which ranges from {1, 2, 3, 4, 5}; E represents the deployment environment, and its value range is {1, 2, 3, 4, 5}; Z represents the disaster recovery level, and its value range is {1, 2, 3, 4, 5}.

4. The information asset risk assessment device according to claim 3, characterized in that: The information asset value determination module includes: A confidentiality value determination unit, configured to obtain a corresponding confidentiality value by weighted calculation based on the enterprise's information asset category data and function data; An integrity value determination unit, configured to obtain a corresponding integrity value by weighted calculation based on the importance data of the information assets of the enterprise; an availability value determination unit, configured to obtain a corresponding availability value by weighted calculation based on the enterprise's information asset service continuity data; The risk level determination unit is used to input the confidentiality assignment, the integrity assignment, the availability assignment, the deployment environment, and the disaster recovery level into a preset information asset value calculation model to determine the information asset value of the enterprise.

5. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the information asset risk assessment method according to any one of claims 1 to 2 are implemented.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the information asset risk assessment method according to any one of claims 1 to 2 are implemented.

7. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the steps of the information asset risk assessment method according to any one of claims 1 to 2 are implemented.

Citation Information

Patent Citations

  • Method and system for evaluating risk of information system

    CN106790198A

  • Information safety risk evaluation system accurate in evaluation

    CN107862205A