Business risk analysis system and business risk analysis method

The business risk analysis system addresses the limitations of historical statistics by calculating the frequency of information security events, enabling precise risk assessment and management through threat and vulnerability analysis.

JP7820268B2Active Publication Date: 2026-02-25HITACHI LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2022149420
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-09-20
Publication Date
2026-02-25
Estimated Expiration
2042-09-20

AI Technical Summary

Technical Problem

Existing methods for estimating business risk due to information security issues rely on historical statistics, which are inadequate for predicting the probability of security incidents, leading to inaccurate risk assessments.

Method used

A business risk analysis system that calculates the frequency of information security events based on the probability of threat realization and vulnerability exploitation using a calculation unit and storage unit, incorporating business configuration information and occurrence probability evaluation information to determine risk values.

Benefits of technology

Enables accurate evaluation of business risks by quantifying the probability and impact of information security events, identifying high-risk operations, and providing targeted risk management strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007820268000001
    Figure 0007820268000001
  • Figure 0007820268000002
    Figure 0007820268000002
  • Figure 0007820268000003
    Figure 0007820268000003
Patent Text Reader

Abstract

To appropriately assess business risks resulting from problems in relation to information security.SOLUTION: Provided is a business risk analysis system having a calculation unit and a storage unit. The storage unit holds business composition information and occurrence probability assessment information. If a value indicating the occurrence probability of the realization of a threat corresponding to the actual state of business components and a value indicating the occurrence probability of exploiting vulnerability are identified based on guide words included in the occurrence probability assessment information, the calculation unit calculates an occurrence frequency of an event related to information security in the business components based on the identified values, calculates the occurrence frequency of the event in the business based on the occurrence frequency of the event in the components, and calculates a risk value of the business based on the occurrence frequency of the event and the magnitude of an impact imparted to the business by the event.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technique for analyzing risks related to information security in a business. [Background technology]

[0002] Non-Patent Document 1 and Patent Document 1 are known as background art in this technical field. Non-Patent Document 1 states, "As a business-level risk analysis method, a method is disclosed for efficiently extracting risks of the entire business, overlooking them, and identifying tasks / systems that should be prioritized for countermeasures." Furthermore, Japanese Patent Application Laid-Open No. 2013-225185 (Patent Document 1) states, "For each task performed using an information system, a disaster countermeasure evaluation device identifies elements that connect service user elements to service provider elements as connecting elements based on the connection relationships of each element constituting the information system, and identifies elements on which the connecting elements depend as dependent elements based on the dependency relationships of each element. The disaster countermeasure evaluation device calculates a damage value for each task in the event of a disaster based on the element downtime period during which the target element will be unavailable if a specified disaster occurs and the evaluation value per unit period of each task, and then calculates the damage value of the information system due to the disaster by summing the damage values ​​for each task." [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2013-225185 [Non-patent literature]

[0004] [Non-Patent Document 1] Yoko Kumagai and five others, "Proposal of a Business-Level Risk Analysis Method for Control Systems," Transactions of the Information Processing Society of Japan, Vol. 60, No. 9, pp. 1518-1527 (Sep. 2019) Summary of the Invention [Problem to be solved by the invention]

[0005] According to the technology described in Non-Patent Document 1, it is possible to evaluate the risk of a business by defining the business as a model. Specifically, Non-Patent Document 1 describes that the risk of a business is evaluated based on the "impact level" that indicates the magnitude of the impact that the risk has on the business.

[0006] Furthermore, the technology described in Patent Document 1 analyzes the disaster risk of information systems deployed in multiple locations and quantitatively displays the results, making it possible to select the most appropriate method from among multiple disaster prevention methods.

[0007] Here, disaster risk is calculated by multiplying the probability of occurrence by the amount of loss that would be incurred if the disaster were to occur. For example, the probability of occurrence is calculated using the statistical value of past disasters.

[0008] To estimate the magnitude of business risk due to information security issues, it is possible to use the same method as above, which is to multiply the probability of occurrence by the magnitude of the loss that would occur if it did occur. However, in this case, the probability of a security incident occurring cannot be estimated simply based on the statistics of the number of times it has occurred in the past. [Means for solving the problem]

[0009] A representative example of the invention disclosed in the present application is as follows: That is, a business risk analysis system includes a calculation unit and a storage unit, the storage unit holds business configuration information and occurrence probability evaluation information, the business configuration information includes information identifying tasks included in a business and components that constitute the tasks, the occurrence probability evaluation information includes information correlating values ​​indicating the probability of an information security threat being realized in the components with guide words that describe the states of the components, and information correlating values ​​indicating the probability of a vulnerability exploitation by the threat occurring in the components with guide words that describe the states of the components, the calculation unit, when a value indicating the probability of the threat being realized and a value indicating the probability of a vulnerability exploitation occurring that correspond to an actual state of the task component based on the guide words included in the occurrence probability evaluation information, calculates a frequency of an information security event occurring in the task component based on the identified values, calculates an occurrence frequency of the event in the task based on the occurrence frequency of the event in the component, and calculates a risk value of the task based on the occurrence frequency of the event and the magnitude of the impact of the event on the business. [Effects of the Invention]

[0010] According to one aspect of the present invention, it is possible to appropriately evaluate business risks caused by information security problems. Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments. [Brief explanation of the drawings]

[0011] [Figure 1A] 1 is a block diagram showing a configuration of a business risk analysis system according to an embodiment of the present invention. [Figure 1B] 1 is a block diagram showing a hardware configuration of a business risk analysis apparatus according to an embodiment of the present invention. [Figure 2] 3 is a flowchart showing a process executed by the business risk analysis device according to the embodiment of the present invention. [Figure 3A]FIG. 1 is an explanatory diagram illustrating a business model in an embodiment of the present invention. [Figure 3B] FIG. 1 is an explanatory diagram illustrating a business process model according to an embodiment of the present invention. [Figure 4] FIG. 1 is an explanatory diagram showing a business configuration clarified in an embodiment of the present invention. [Figure 5] 10 is a flowchart showing a process in which the business risk analysis device according to the embodiment of the present invention identifies a task related to the output of a business. [Figure 6] FIG. 10 is an explanatory diagram of the classification of tasks identified in the embodiment of the present invention. [Figure 7A] FIG. 2 is a specific explanatory diagram of the related tasks of online processing task extraction and intended output in an embodiment of the present invention. [Figure 7B] FIG. 10 is a specific illustration of the related business of unintended output in an embodiment of the present invention. [Figure 8] FIG. 10 is an explanatory diagram of related business information identified in the embodiment of the present invention. [Figure 9] 1 is a flowchart showing a process performed by the business risk analysis device according to the embodiment of the present invention to evaluate the probability of an event occurring. [Figure 10] FIG. 2 is an explanatory diagram showing an occurrence probability evaluation table relating to people, which is held by the business risk analysis device according to the embodiment of the present invention. [Figure 11] 1 is an explanatory diagram showing an occurrence probability evaluation table relating to a system / device, which is held by a business risk analysis device according to an embodiment of the present invention. [Figure 12] FIG. 2 is an explanatory diagram showing an occurrence probability evaluation table relating to inputs, specifications, and plans, which is held by the business risk analysis device according to the embodiment of the present invention. [Figure 13A] FIG. 1 is an explanatory diagram showing an occurrence frequency calculation table relating to input, specifications, plans, and people, which is held by the business risk analysis device according to an embodiment of the present invention. [Figure 13B] FIG. 2 is an explanatory diagram showing an occurrence frequency calculation table relating to systems and devices, which is held by the business risk analysis device according to the embodiment of the present invention. [Figure 14] FIG. 10 is an explanatory diagram showing the results of the business risk analysis device according to the embodiment of the present invention identifying the occurrence frequency of events in each related business. [Figure 15] FIG. 1 is an explanatory diagram showing the results of an evaluation of possible events and their impacts by a business risk analysis device according to an embodiment of the present invention. [Figure 16] FIG. 2 is an explanatory diagram showing a risk value calculation table held by the business risk analysis apparatus according to the embodiment of the present invention. [Figure 17] FIG. 10 is an explanatory diagram showing the results of calculation of the risk value of each business by the business risk analysis device according to the embodiment of the present invention. [Figure 18] FIG. 2 is an explanatory diagram showing a first example of information output as a processing result by the business risk analysis apparatus according to the embodiment of the present invention. [Figure 19] FIG. 10 is an explanatory diagram showing a second example of information output as a processing result by the business risk analysis apparatus according to the embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0013] FIG. 1A is a block diagram showing the configuration of a business risk analysis system according to an embodiment of the present invention.

[0014] The business risk analysis system of this embodiment is configured by a business risk analysis device 11 and a user terminal 12 that are communicably connected via a network 13 .

[0015] FIG. 1B is a block diagram showing the hardware configuration of a business risk analysis apparatus 11 according to an embodiment of the present invention.

[0016] The business risk analysis device 11 is realized by a system having, for example, a calculation unit 111, a storage unit 112, an input unit 113, a display unit 114, and a communication unit 115.

[0017] The calculation unit 111 can be configured using a calculation device such as a CPU (Central Processing Unit). In the following description, the processing executed by the business risk analysis device 11 is realized by the function of the calculation unit 111. The function of the calculation unit 111 can be configured using a circuit device that implements that function, or can be configured by the calculation unit 111 executing software that implements that function (for example, a business risk analysis program 121 described below).

[0018] The memory unit 112 is a storage device that stores software executed by the calculation unit 111, information referenced in the processing executed by the calculation unit 111, information generated as a result of the processing, etc. The memory unit 112 may include, for example, a main storage device such as a DRAM (Dynamic Random Access Memory) and an auxiliary storage device such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive). The memory unit 232 of this embodiment stores a business risk analysis program 121, business configuration information 122, related business information 123, an occurrence probability evaluation table 124, an occurrence frequency calculation table 125, impact information 126, and a risk value calculation table 127.

[0019] The business risk analysis program 121 is a program for causing the calculation unit 111 to execute the processing of the business risk analysis device 11, which will be described later with reference to flowcharts and the like. That is, the processing of the business risk analysis device 11, which will be described later with reference to flowcharts and the like, is executed by the calculation unit 111 in accordance with the business risk analysis program 121. The business risk analysis program 121 may be introduced into the business risk analysis device 11 via the network 13 from a non-volatile or non-transitory storage medium of an external device (not shown) connected to the network 13, or may be introduced into the business risk analysis device 11 via a portable non-volatile or non-transitory storage medium. Details of the business configuration information 122 to the risk value calculation table 127 will be described later.

[0020] The input unit 113 is a device that accepts input of information from an administrator or a user of the business risk analysis device 11, and may include, for example, at least one of a keyboard, a mouse, and a touch panel. The display unit 114 is a device that outputs information to an administrator or a user of the business risk analysis device 11, and may be, for example, an image display device. The communication unit 115 is connected to the network 13 and communicates with other devices. In the example of FIG. 1B, the communication unit 115 communicates with the user terminal 12 via the network 13.

[0021] Each user terminal 12 may be, for example, a portable or desktop PC (Personal Computer), a so-called tablet terminal, or a so-called smartphone, owned by each user of the business risk analysis device 11. Possible users of the business risk analysis device 11 are, for example, sales representatives of businesses that provide security measures, or system personnel of businesses that are planning to introduce security measures into their companies, but the following description will be given taking the former user as an example.

[0022] The user may directly operate the business risk analysis device 11 without using the user terminal 12, or if the functions of the business risk analysis device 11 can be implemented in the user terminal 12, the user may use the user terminal 12 as the business risk analysis device 11. In the latter case, the configuration of the user terminal 12 may be the same as that shown in FIG. 1B.

[0023] FIG. 2 is a flowchart showing the processing executed by the business risk analysis device 11 according to the embodiment of the present invention.

[0024] An example will be described below in which a sales representative (user) of a company that provides security measures proposes security measures to a client company that is the recipient of the measures.

[0025] First, the user conducts an interview with the client company to clarify the structure of the client's business, and inputs the results into the business risk analysis device 11 (step S1001). Details of this process will be described later with reference to FIGS. 3A to 4.

[0026] Next, the user identifies the business related to the output of the customer's business (i.e., related business) based on the interview or the like, and inputs the results to the business risk analysis device 11 (step S1002). Details of this process will be described later with reference to Figs. 5 to 8.

[0027] Next, the business risk analysis device 11 evaluates the probability of occurrence of an undesirable event related to information security in the business 301 based on the information on the components of the related business (step S1004). Details of this process will be described later with reference to Figs. 9 to 14.

[0028] Next, the business risk analysis device 11 extracts possible events based on the output of the business and evaluates the impact of these events on the business (step S1005). Details of this process will be described later with reference to FIG.

[0029] Next, the business risk analysis device 11 calculates the magnitude (risk value) of each business risk based on the evaluated occurrence probability and impact (step S1006). Details of this process will be described later with reference to Figs. 16 and 17.

[0030] Finally, the business risk analysis device 11 outputs business risks with high risk values ​​and the operations related to them (step S1007). Details of this process will be described later with reference to FIGS.

[0031] 3A and 3B are explanatory diagrams showing a business model and a business operation model, respectively, in an embodiment of the present invention.

[0032] The business configuration in step S1001 is clarified based on a business model and a business operation model. As shown in Fig. 3A, a business 301 receives input 302, performs a predetermined task (described later), and outputs output 303. This business 301 is carried out based on a standard / plan 306, and resources such as people 307 and systems / devices 308 are invested in order to carry it out.

[0033] For example, if business 301 is a business that manufactures parts, input 302 is the raw materials for the parts, and standard / plan 306 is at least one of the standard for manufacturing the parts and the manufacturing plan. Here, input 302 and standard / plan 306 are distinguished, but they may all be included in input 302. People 307 are people involved in the business (e.g., designers, manufacturing workers, etc.), and system / equipment 308 is at least one of the system and equipment used in the business.

[0034] Output 303 includes intended output 304, such as the results of the business, and unintended output 305. For example, in the case of a parts manufacturing business, manufactured parts would be intended output 304. In addition, waste that is naturally generated even when manufacturing is performed normally is also included in intended output 304. On the other hand, waste (e.g., defective parts) generated when manufacturing is not performed normally is unintended output 305. Information may also be included as unintended output 305. For example, if design information that is originally confidential is leaked, that information would be unintended output 305.

[0035] In the above explanation, a business that manufactures parts was given as an example of business 301, but business 301 may be any other business. For example, if business 301 is a business that provides some kind of information service, input 302 may be order information from customers of that business, intended output 304 may be information provided by the service, and unintended output 305 may be confidential information related to the service (for example, personal information of customers, etc.).

[0036] Business 301 is generally made up of one or more tasks. Figure 3B shows an example of business 301 made up of two tasks. In the example of Figure 3B, business 301 is made up of a first task 311-1 and a second task 311-2. In the following explanation, when multiple tasks are not distinguished and an explanation common to all of them is given, they will be written as business 311, and when each task is distinguished and explained, they will be written with a subnumber, such as business 311-1. The same applies to other components.

[0037] Task 311-1 receives input 312-1 and outputs output 316-1. Output 316-1 is input to the next task 311-2. This task 311-1 is performed based on standards / plans 313-1, and resources such as people 314-1 and systems / devices 315-1 are used to carry out the task.

[0038] When an output 316-1 of the task 311-1 is input, the task 311-2 outputs an output 316-2. The task 311-2 is performed based on a standard / plan 313-2, and resources such as people 314-2 and systems / devices 315-2 are used to carry out the task.

[0039] Input 312-1 corresponds to input 302 of business 301, and output 316-2 corresponds to output 303 of business 301. Standards / Plan 313-1 and Standards / Plan 313-2 are each at least a part of Standards / Plan 306. Person 314-1 and Person 314-2 are each at least a part of Person 307. System / Device 315-1 and System / Device 315-2 are each at least a part of System / Device 308.

[0040] FIG. 4 is an explanatory diagram showing the business configuration clarified in the embodiment of the present invention.

[0041] In the example of FIG. 4, it is clarified that the business 301 is made up of a purchasing operation 311-3, a parts manufacturing operation 311-4, a shipping management operation 311-5, an R&D (research and development) operation 311-6, and a design operation 311-7.

[0042] In this example, business 301 is a business that manufactures parts, input 302 is the raw material iron, and output 304 includes at least the manufactured parts. The input 312-3 and output 316-3 of purchasing task 311-3 are both iron. An inventory manager is input as person 314-3 to purchasing task 311-3, and an inventory management system is input as system / device 315-3.

[0043] In addition, when the input 312-3 and the output 316-3 are iron as described above, they may be described as iron 312-3 and iron 316-3. The same applies to other components. The same applies to other business components described later.

[0044] The parts manufacturing operation 311-4 receives as input iron, which is output 316-3 of the purchasing operation 311-3, and design information, which is output 316-7 of the design operation 311-7. The parts manufacturing operation 311-4 is carried out based on the production plan, which is the specification / plan 313-4, with workers input as people 314-4 and manufacturing systems and molding equipment input as systems / equipment 315-4, and parts output as output 316-4.

[0045] The shipping management task 311-5 receives input of parts, which are output 316-4 of the parts manufacturing task 311-4, and inputs a shipping manager as person 314-5 and a shipping management system and shipping warehouse as system / device 313-5. The parts are output as output 316-5 of the shipping management task 311-5.

[0046] In the R&D task 311-6, researchers are input as people 314-6 and a research system is input as system / equipment 315-6. The output 316-6 of the R&D task 311-6 is the research result. In the design task 311-7, the research result which is the output 316-6 of the R&D task 311-6 is input, and a designer is input as person 314-7 and a design system is input as system / equipment 315-7. The output 316-7 of the design task 311-7 is design information.

[0047] Part 304-1 of intended output 304 constituting output 303 of business 301 corresponds to part 316-5, which is output from shipping management task 311-5. Meanwhile, waste 305-1, which corresponds to goods among unintended output 305, is expected to be output from part manufacturing task 311-4. Here, waste 305-1 is not waste that would naturally be generated if parts manufacturing were carried out normally, but waste that occurs due to some kind of problem in the business. Here, possible problems include, for example, poor input such as low-quality iron or incorrect design information, errors in production planning, operational mistakes by workers, or malfunctions in the manufacturing system, etc.

[0048] Furthermore, design information 305-2 corresponding to information among the unintended outputs 305 is information that is originally confidential but has been leaked, and is assumed to be output from the parts manufacturing task 311-4 or the design task 311-7.

[0049] As described above, the tasks 311 that make up the business 301, the resources invested in each task, and the inputs and outputs of each task are clarified, and information indicating these is held in the business risk analysis device 11 as business configuration information 122.

[0050] FIG. 5 is a flowchart showing the process of identifying a task related to the output of a business by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0051] Specifically, FIG. 5 provides a detailed explanation of the processing performed in step S1002 of FIG.

[0052] First, the user classifies the tasks 311 included in the business 301 into "main activities" and "support activities" in the value chain based on interviews with the client company, etc., and inputs the results into the business risk analysis device 11 (step S2001). Details of this process will be described later with reference to FIG. 6.

[0053] Next, the user extracts online processing operations from the operations 311 included in the business 301 based on interviews with the client business operators, and inputs the results into the business risk analysis device 11 (step S2002). Details of this processing will be described later with reference to FIG. 7A.

[0054] Next, the business risk analysis device 11 identifies the related business of the intended output (step S2003) and the related business of the unintended output (step S2004), and inputs these results into the business risk analysis device 11. Details of these processes will be described later with reference to Figures 7A and 7B.

[0055] Finally, the business risk analysis device 11 organizes the relationship between each output and the business 311 (step S2005). Details of this process will be described later with reference to FIG.

[0056] FIG. 6 is an explanatory diagram of the classification of tasks identified in the embodiment of the present invention.

[0057] Here, an example is shown in Figure 4 where the identified tasks 311 are classified into "main activities" and "support activities." In a typical value chain analysis, a "main activity" is classified as an activity that directly creates value. For example, among the identified tasks 311, purchasing task 311-3, parts manufacturing task 311-4, and shipping management task 311-5 are classified as main activities. In Figure 6, these tasks are shown with bold frames. On the other hand, a "support activity" is classified as an activity that supports the main activity. For example, among the identified tasks 311, R&D task 311-6 and design task 311-7 are classified as support activities. Note that this classification is just an example, and the user can make appropriate classifications based on the results of interviews, etc.

[0058] FIG. 7A is a specific explanatory diagram of the related tasks of extracting tasks and intended output of online processing in an embodiment of the present invention.

[0059] Here, an example is shown in which online processing tasks are extracted from the identified tasks 311 as shown in Fig. 4, and tasks related to the intended output are further identified. Online processing tasks are tasks 311 that are executed immediately after input and whose results are output.

[0060] In the example of Figure 7A, parts manufacturing task 311-4 and shipping management task 311-5 are identified as tasks that require real-time online processing. On the other hand, purchasing task 311-3 is not extracted as an online processing task because it is not performed in real-time, for example, once a day, using steel that has been input up to that point. R&D task 311-6 and design task 311-7 are also not extracted as online processing tasks because they are not performed in real-time.

[0061] Since online processing tasks are performed instantly, if a security risk occurs, undesirable events such as output stoppage, output delay, or unauthorized output are likely to occur. In this embodiment, such tasks are extracted as tasks with higher analysis importance. However, whether each task corresponds to online processing depends on the actual situation of each task. Therefore, it is desirable for the user to appropriately extract online processing tasks in accordance with the actual situation of the task based on the results of interviews, etc. Furthermore, if it is desired to analyze all tasks without setting importance, step S2002 may be skipped.

[0062] 7A shows an example in which parts manufacturing task 311-4 and shipping management task 311-5 are identified as tasks related to the intended output. This is because part 304-1, which is the intended output, is manufactured by parts manufacturing task 311-4 and output via shipping management task 311-5.

[0063] FIG. 7B is a specific illustration of the relevant business of unintended output in an embodiment of the present invention.

[0064] 7B shows an example in which parts manufacturing work 311-4 and design work 311-7 are identified as related works of the unintended output. This is because waste 305-1, which is an unintended output, is output from parts manufacturing work 311-4, and design information 305-2, which is an unintended output, is output from parts manufacturing work 311-4 and design work 311-7.

[0065] The business risk analysis device 11 can identify the related businesses shown in Figures 7A and 7B based on the business configuration information 122 shown in Figure 4. The identified related businesses are stored in the storage unit 112 of the business risk analysis device 11 as, for example, related business information 123 shown in Figure 8.

[0066] FIG. 8 is an explanatory diagram of the related business information 123 identified in the embodiment of the present invention.

[0067] The related task information 123 includes an output type 801, an output 802, and a related task 803. The output type 801 indicates the type of each output (i.e., whether it is an intended output or an unintended output). The output 802 indicates the content of each output. The related task 803 indicates the task related to each output.

[0068] The related business information 123 based on the business configuration information 122 shown in Figure 4 above indicates that the intended output, parts 304-1, is related to parts manufacturing business 311-4 and shipping management business 311-5, that the unintended output, waste 305-1, is related to parts manufacturing business 311-4, and that the unintended output, design information 305-2, is related to parts manufacturing business 311-4 and design business 311-7.

[0069] FIG. 9 is a flowchart showing the process of evaluating the probability of an event occurring by the business risk analysis device 11 according to the embodiment of the present invention.

[0070] First, the user presents the occurrence probability evaluation table 124 and the occurrence frequency calculation table 125 to the customer business operator and agrees on the contents (step S3001). Details of the occurrence probability evaluation table 124 and the occurrence frequency calculation table 125 will be described later with reference to Figs. 10 to 13B.

[0071] Next, the business risk analysis device 11 evaluates the probability of occurrence of a risk in each component of any related business from the perspective of "threat realization" based on the occurrence probability evaluation table 124 (step S3002). Next, the business risk analysis device 11 evaluates the probability of occurrence of a risk in each component from the perspective of "vulnerability exploitation" based on the occurrence probability evaluation table 124 (step S3003). Next, the business risk analysis device 11 identifies the probability of occurrence of a risk in each component based on the evaluation results of steps S3002 and S3003 (step S3004).

[0072] Next, the business risk analysis device 11 determines whether evaluation has been completed for all components of the related business (step S3005). If there are components for which evaluation has not been completed (step S3005: No), the business risk analysis device 11 executes steps S3002 to S3004 for the components for which evaluation has not been completed. If evaluation has been completed for all components (step S3005: Yes), the business risk analysis device 11 adopts the highest value among the evaluation results of the components as the probability of occurrence of risk in the related business (step S3006).

[0073] Next, the business risk analysis device 11 determines whether evaluation has been completed for all related businesses (step S3007). If there are related businesses for which evaluation has not been completed (step S3007: No), the business risk analysis device 11 executes steps S3002 to S3006 for the related businesses for which evaluation has not been completed. If evaluation has been completed for all related businesses (step S3007: Yes), the process ends.

[0074] FIG. 10 is an explanatory diagram showing the occurrence probability evaluation table 124 relating to people, which is held by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0075] Specifically, FIG. 10 shows a portion 124-1 of the occurrence probability evaluation table 124 relating to the person 314, which is a component of the task 311.

[0076] The occurrence probability evaluation table 124 includes components 1001 , viewpoints 1002 , sub-viewpoints 1003 , scales 1004 and guide words 1005 .

[0077] The component 1001 is information that identifies the component of the business 311. In the example of Fig. 10, the value of the component 1001 is "person".

[0078] The viewpoint 1002 indicates a viewpoint for risk assessment. In this embodiment, the value of the viewpoint 1002 is either "threat realization" or "vulnerability exploitation." Here, the frequency of threat realization refers to the probability that an information security threat occurs, and the probability of vulnerability exploitation refers to the probability that a threat that occurs exploits a vulnerability in a system or the like. For example, a threat realization corresponds to a virus reaching a business system, and vulnerability exploitation corresponds to the virus breaching security measures implemented in the business system. These may be, for example, those described in IEC 62443-2-1. When a threat occurs and the threat is able to exploit a system vulnerability, an undesirable event related to information security is considered to occur.

[0079] The scale 1004 is a value indicating the degree of probability of occurrence of each aspect (i.e., the realization of a threat or the exploitation of a vulnerability). In the example of Fig. 10, the value of the scale 1004 is "high," indicating a high probability of occurrence, "medium," indicating a medium probability of occurrence, or "low," indicating a low probability of occurrence. These values ​​are merely examples, and values ​​other than those above, such as more specific probability numerical values, may also be used.

[0080] The guide word 1005 is information that expresses the state of each component, corresponding to the occurrence probability of each aspect in each component.

[0081] It may be easier to set appropriate guide words by further classifying the combinations of components and viewpoints. For this purpose, a sub-viewpoint 1003 may be set. This classification may be performed as needed, and in the example of FIG. 10, a sub-viewpoint 1003 is not set.

[0082] In the example of Fig. 10, the guide words 1005 corresponding to the "low," "medium," and "high" scales of the probability of occurrence of the "threat realization" perspective of the component "people" are "a system of personal authentication is in place and audits are conducted regularly," "a system of personal authentication or audits is partially in place," and "a system of personal authentication or audits is not in place," respectively. This indicates that the probability of occurrence of the threat realization is evaluated as follows for people 314, a component of business 311. That is, if there is a system of personal authentication and audits are conducted regularly, the probability of occurrence of the threat realization is evaluated as low; if there is a system of personal authentication or audits partially in place, the probability of occurrence of the threat realization is evaluated as medium; and if there is no system of personal authentication or audits, the probability of occurrence of the threat realization is evaluated as high.

[0083] On the other hand, the guide words 1005 corresponding to the "low," "medium," and "high" scales of the probability of vulnerability exploitation from the viewpoint of the component "people" are "regularly provide education and training," "provide education at the beginning," and "no education or training program," respectively. This indicates that the probability of vulnerability exploitation is evaluated as follows for people 314, a component of business 311. That is, if education and training for people to reduce risk are regularly provided, the probability of vulnerability exploitation is evaluated as low; if education is provided initially (for example, when joining the company or taking up a position), the probability of vulnerability exploitation is evaluated as medium; and if there is no education and training program, the probability of vulnerability exploitation is evaluated as high.

[0084] FIG. 11 is an explanatory diagram showing an occurrence probability evaluation table 124 relating to a system / device, which is held by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0085] Specifically, FIG. 11 shows a portion 124-2 of the occurrence probability evaluation table 124 relating to the system / device 315, which is a component of the business 311.

[0086] 11, the value of the component 1001 is "person." Also, the sub-perspectives 1003 corresponding to the value of the perspective 1002, "threat realization," include "network" and "component."

[0087] The guide words 1005 corresponding to the probability scales "low," "medium," and "high" of the perspective "threat realization" and the sub-perspective "network" of the component "system / device" are "isolated from other networks," "connected to a private network with a dedicated line," and "connected to a public network such as the Internet," respectively. This indicates that the probability of a threat realizing in a network is evaluated as follows for system / device 315, a component of business 311. That is, if the system or device is isolated from other networks, the probability of the threat realizing is evaluated as low; if it is connected to a private network such as a dedicated line, the probability of the threat realizing is evaluated as medium; and if it is connected to a public network such as the Internet, the probability of the threat realizing is evaluated as high.

[0088] The guide words 1005 corresponding to the probability scales "low," "medium," and "high" of the "threat realization" perspective and the "component" sub-perspective of the "system / device" component are "hardly uses a general-purpose OS / middleware / application," "some general-purpose OS / middleware / application is used," and "general-purpose OS / middleware / application is used," respectively. This indicates that the probability of a threat being realized in a component, such as a system / device 315, which is a component of a business operation 311, is evaluated as follows: If the system or device uses almost no general-purpose components, such as an OS (operating system), middleware, or application (e.g., less than 30% of the components used are general-purpose), the probability of the threat being realized is evaluated as low; if the system or device uses some general-purpose components (e.g., 30% to 70% of the components are general-purpose), the probability of the threat being realized is evaluated as medium; and if the system or device uses general-purpose components (e.g., 70% or more of the components are general-purpose), the probability of the threat being realized is evaluated as high.

[0089] The guide words 1005 corresponding to the "low," "medium," and "high" scales of the probability of vulnerability exploitation from the viewpoint of the component "system / device" are "system development / construction with security in mind and implementation of security operation and maintenance," "security is considered to some extent, but updated security status (vulnerabilities, etc.) is not caught," and "security is not particularly considered in design and development," respectively. This indicates that the probability of vulnerability exploitation is evaluated as follows for system / device 315, a component of business 311. That is, if security is considered when the system or device is developed or constructed and security operation and maintenance is implemented, the probability of vulnerability exploitation is evaluated as low; if security is considered to some extent but updated security status is not caught, the probability of vulnerability exploitation is evaluated as medium; and if security is not considered, the probability of vulnerability exploitation is evaluated as high.

[0090] FIG. 12 is an explanatory diagram showing an occurrence probability evaluation table 124 relating to inputs, specifications, and plans, which is held by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0091] Specifically, FIG. 12 shows a portion 124-4 of the occurrence probability evaluation table 124 relating to the input 312 and the standard / plan 313, which are components of the task 311.

[0092] In the example of FIG. 12, the value of component 1001 is "Input, Standard / Plan."

[0093] The guide words 1005 corresponding to the scales of "low," "medium," and "high" of the probability of occurrence of the perspective "threat realization" of the component "input, standard / plan" are "received via an internal network (LAN, local area network, etc.) or passed by an insider on premises accessible only to insiders," "received via a wide area network (WAN, wide area network, etc.) or received via an insider, but may also be accessible to outsiders," and "received via the Internet or received via an outsider," respectively. This indicates that the probability of occurrence of threat realization is evaluated as follows for input, standard, or plan, which are components of business 311. In other words, if the input, standard, or plan is obtained via an internal network such as a LAN, or is obtained from an insider on premises accessible only to insiders, the probability of the threat being realized is assessed as low; if it is obtained via a wide area network such as a WAN, or is obtained from an insider but may also be accessible to outsiders, the probability of the threat being realized is assessed as medium; and if it is obtained via the Internet or via an outsider, the probability of the threat being realized is assessed as high.

[0094] The guide words 1005 corresponding to the "low," "medium," and "high" scales of the probability of vulnerability exploitation from the perspective of the component "input, standards / plans" are "there is a system to check received input (technically available)," "received input is simply checked (visual check, etc.)," ​​and "there is no system to check received input," respectively. This indicates that the probability of vulnerability exploitation is evaluated as follows for input, standards, or plans, which are components of business 311. That is, if there is a technical system to check the input, standards, or plans when they are obtained, the probability of vulnerability exploitation is evaluated as low; if there is a system to perform a simple check such as a visual check, the probability of vulnerability exploitation is evaluated as medium; and if there is no checking system, the probability of vulnerability exploitation is evaluated as high.

[0095] FIG. 13A is an explanatory diagram showing an occurrence frequency calculation table 125 relating to inputs, specifications, plans, and people, which is held by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0096] The occurrence frequency calculation table 125 is a table for calculating the frequency of occurrence of undesirable events based on the evaluated occurrence probabilities of threats being realized and vulnerabilities being exploited. Specifically, the table holds the value of the occurrence frequency of an event (i.e., a value indicating the degree of the probability of an event occurring) corresponding to the combination of the probability 1402 of the risk of threats being realized and the probability 1401 of the risk of vulnerability exploitation.

[0097] 13A shows an occurrence frequency calculation table 125-1 for calculating the occurrence frequency of an event based on the occurrence probability of a threat being realized and a vulnerability being exploited regarding input 312, standard / plan 313, and person 314, which are components of business 311. In this example, when both the occurrence probability of a threat being realized and the occurrence probability of a vulnerability being exploited are "high," the occurrence frequency of the event is "5." Note that in this example, the larger the numerical value of the occurrence frequency of the event, the higher the occurrence frequency.

[0098] Similarly, if one of the probability of a threat realizing or the probability of a vulnerability exploitation is "high" and the other is "medium," the frequency of the event is "4." If one of the probability of a threat realizing or the probability of a vulnerability exploitation is "high" and the other is "low," or if both are "medium," the frequency of the event is "3." If one of the probability of a threat realizing or the probability of a vulnerability exploitation is "medium" and the other is "low," the frequency of the event is "2." If both the probability of a threat realizing or the probability of a vulnerability exploitation are "low," the frequency of the event is "1."

[0099] FIG. 13B is an explanatory diagram showing the occurrence frequency calculation table 125 relating to systems and devices, which is held by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0100] 13B shows an occurrence frequency calculation table 125-2 for calculating the occurrence frequency of an event based on the occurrence probability of the realization of a threat and the exploitation of a vulnerability related to the system / device 315 among the components of the business 311. As shown in FIG. 11, values ​​according to two sub-perspectives are set for the realization of a threat, and therefore in this example, the occurrence frequency of an event according to the combination of these two values ​​and the value of the probability of the exploitation of a vulnerability is held.

[0101] Specifically, if the probability of occurrence of two sub-perspectives of a threat realizing is both "high", or one is "high" and the other is "medium", if the probability of occurrence of the risk of vulnerability exploitation is "high", the frequency of occurrence of the event will be "5", if the probability of occurrence of vulnerability exploitation is "medium", the frequency of occurrence of the event will be "4", and if the probability of occurrence of vulnerability exploitation is "low", the frequency of occurrence of the event will be "3".

[0102] If the probability of occurrence of two sub-perspectives of a threat realization is both "medium", or one is "high" and the other is "low", if the probability of vulnerability exploitation is "high", the frequency of the event will be "4", if the probability of vulnerability exploitation is "medium", the frequency of the event will be "3", and if the probability of vulnerability exploitation is "low", the frequency of the event will be "2".

[0103] If the probability of occurrence of two sub-perspectives of a threat realization is both "low", or one is "medium" and the other is "low", if the probability of vulnerability exploitation is "high", the frequency of the event will be "3", if the probability of vulnerability exploitation is "medium", the frequency of the event will be "2", and if the probability of vulnerability exploitation is "low", the frequency of the event will be "1".

[0104] The method of creating the tables shown in Figures 10 to 13B is not limited. For example, the user may create these tables based on interviews with customer businesses, or may use pre-prepared templates, or may create the tables by modifying pre-prepared templates based on the results of the interviews. Such creation and confirmation work may be performed in step S3001 of Figure 9.

[0105] In steps S3002 and S3003, for example, the user may grasp the status of each component of each operation of the client company's business by interviewing the client company, compare this with the guide words 1005 shown in Figures 10 to 12, and obtain a measure 1004 corresponding to the relevant guide word 1005, thereby identifying the probability of threats for each component becoming a reality and vulnerabilities being exploited.

[0106] 13A and 13B is an example of information for calculating the occurrence frequency, and other information may be used. As described above, since an event is considered to occur when a threat materializes and the threat exploits a vulnerability, the occurrence frequency of the event is calculated so that the higher the probability of the threat materializing, the higher the occurrence frequency of the event, and the higher the probability of the vulnerability exploitation. For example, if the probability of the threat materializing and the probability of the vulnerability exploitation are expressed as numbers from 0 to 1 or from 0% to 100%, a formula for calculating the occurrence frequency of the event by multiplying the two probabilities may be used as information for calculating the occurrence frequency instead of occurrence frequency calculation table 125.

[0107] FIG. 14 is an explanatory diagram showing the results of the business risk analysis apparatus 11 according to the embodiment of the present invention specifying the occurrence frequency of events in each related business.

[0108] That is, Figure 14 is an example of information obtained as a result of executing step S3006 in Figure 9. This information includes related tasks 1501, components 1502, evaluation results and reasons 1503, component occurrence frequencies 1504, and related task occurrence frequencies 1505. Related tasks 1501 is information that identifies related tasks among the tasks 311 that make up the business 301. Components 1502 is information that identifies the components of related tasks. Evaluation results and reasons 1503 indicates the evaluation results and reasons for the probability of threats being realized and vulnerabilities being exploited in each component. Component occurrence frequencies 1504 indicate the frequency of events occurring in each component. Related task occurrence frequencies 1505 indicate the frequency of events occurring in each related task.

[0109] Here, the example of FIG. 14 will be described. The inputs of the components of the related component manufacturing task 311-4 are steel and design information. As a result of interviewing the person about the input of the design information, if it is found that the design information was obtained via an internal LAN and that the person in charge had visually confirmed that it had been approved, this corresponds to the guide words 1005 shown in FIG. 12, "received via an internal network (e.g., LAN)" and "perform a simple check of the received input (e.g., visual confirmation)," the probability of the threat relating to the input of the design information being realized is determined to be "low," and the probability of the vulnerability being exploited is determined to be "medium" (steps S3002 to S3004). By comparing these results with the occurrence frequency calculation table 125-1 shown in FIG. 13A, the occurrence frequency of the event in the input of design information to the component manufacturing task 311-4 is determined to be "2," and this is stored as the occurrence frequency 1504 of the component (step S3006).

[0110] Similarly, if the frequency of occurrence of events in the components of parts manufacturing business 311-4, such as iron, workers, manufacturing systems, shaping equipment, and production plans, is identified and the results are "2," "1," "4," "2," and "1," respectively, the largest value among these, "4," is adopted as the frequency of occurrence of events in parts manufacturing business 311-4 and is retained as the frequency of occurrence of related business 1505.

[0111] Similar processing is performed for the other related tasks, shipping management task 311-5 and design task 311-7, and the occurrence frequencies 1505 of the related tasks are identified as "3" and "5", respectively.

[0112] FIG. 15 is an explanatory diagram showing the results of an evaluation of possible events and their impacts by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0113] 15 is an example of impact information 126 obtained as a result of executing step S1005 in FIG. 2. This information includes output items 1601, HAZOP guide words 1602, occurring events 1603, viewpoints 1604, business risks 1605, and impacts 1606. The output items 1601 are information that specifies the output of the business. The HAZOP guide words 1602 indicate the type of event that may occur corresponding to the output of the business. For example, the type may be based on the guide words of HAZOP (Hazard and Operability Studies), or if other type information is available, that may be used.

[0114] Occurring event 1603 indicates an event that is expected to actually occur in response to the output and the type of event. Viewpoint 1604 indicates the targets (for example, people, the environment, and organizations) that will be affected if the expected event occurs. Business risk 1605 is information that expresses the details of the impact if the expected event occurs. Impact 1606 indicates the magnitude of the impact if the expected event occurs. The level of impact of the event for each viewpoint may conform to a known standard, such as IEC 62443-2-1.

[0115] The output item 1601 holds information indicating all outputs expected in the business 301, such as parts 304-1, which are intended outputs 304, waste 305-1, which are unintended outputs 305, and design information 305-2. The HAZOP guide words 1602 corresponding to "parts" hold "no" (no output), "invalid" (invalid output), "much" (excessive output), and "less" (insufficient output) as types of events related to the output of parts. The corresponding occurrence events 1603 are "production of parts stops," "invalid parts are produced," "excessive parts are produced," and "insufficient production of parts," respectively.

[0116] On the other hand, for the unintended outputs of "waste" and "design information," it is desirable that they not be output, so the values ​​of the HAZOP guide words 1602 corresponding to them are all "output," and "unexpected waste is produced" and "design information is leaked," respectively, are stored as occurring events 1603.

[0117] For example, in the case of parts output, if an event occurs in which "production of parts stops," the impact this will have on the organization (business risk 1605) is expected to be something like "production of parts stops, causing a loss of customer trust," and the impact 1606 is evaluated as "large."

[0118] On the other hand, if an event occurs in which "illegal output is produced" for the output of parts, the impact on people is expected to be "illegal parts are produced, causing injury to the customer (user)," and the impact 1606 is evaluated as "medium." Furthermore, the impact on the organization is expected to be "illegal parts are produced, causing loss of customer trust," and the impact 1606 is evaluated as "medium."

[0119] In this way, the content and degree of impact (magnitude of impact) on each target when an event of each type corresponding to the output 303 of the business 301 occurs is evaluated and stored in the storage unit 112. This evaluation can be made by the user based on interviews with customers.

[0120] FIG. 16 is an explanatory diagram showing the risk value calculation table 127 held by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0121] The risk value calculation table 127 holds risk values ​​corresponding to the value of impact 1701 and the value of occurrence frequency 1702. Here, impact 1701 corresponds to the value of impact 1606 in Fig. 15, and occurrence frequency 1702 corresponds to the occurrence frequency of related work 1505 in Fig. 14. The risk value is set so that the larger the value of impact 1701, the larger the risk value, and so that the larger the occurrence frequency 1702, the larger the risk value.

[0122] For example, when the impact 1701 is "large," the risk values ​​corresponding to the occurrence frequency 1702 values ​​"5," "4," "3," "2," and "1" may be set to "5," "4," "3," "2," and "1," respectively. When the impact 1701 is "medium," the risk values ​​corresponding to the occurrence frequency 1702 values ​​"5," "4," "3," "2," and "1" may be set to "4," "3," "2," "1," and "1," respectively. When the impact 1701 is "low," the risk values ​​corresponding to the occurrence frequency 1702 values ​​"5," "4," "3," "2," and "1" may be set to "3," "2," "1," "1," and "1," respectively.

[0123] FIG. 17 is an explanatory diagram showing the results of calculation of the risk value of each business by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0124] The risk value calculation result shown in Fig. 17 includes related work 1801, occurrence frequency 1802, and risk value 1803 in addition to output items 1601 to impact 1606 similar to those shown in Fig. 15. Explanation of output items 1601 to impact 1606 will be omitted.

[0125] Related work 1801 indicates the related work of each output. Occurrence frequency 1802 indicates the occurrence frequency of an assumed event in each related work. Risk value 1803 indicates the risk value of each related work calculated based on impact 1606 and occurrence frequency 1802.

[0126] For example, if an event occurs in which "production of parts is stopped" with respect to the output of parts, the impact (business risk 1605) that this would have on the organization would be expected to be "production of parts is stopped, and customer trust is lost," and the impact 1606 would be evaluated as "large." Furthermore, as shown in Figure 14, the frequency of occurrence of events in parts manufacturing operation 311-4 and shipping management operation 311-5, which are operations related to the output of parts, is "4" and "3," respectively. Therefore, based on the risk value calculation table 127 in Figure 16, the risk values ​​of the events in parts manufacturing operation 311-4 and shipping management operation 311-5 are calculated to be "4" and "3," respectively. Risk values ​​for other events related to the output of parts and risk values ​​related to other outputs are calculated in a similar manner.

[0127] FIG. 18 is an explanatory diagram showing a first example of information output as a processing result by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0128] Specifically, Fig. 18 is an example of information output in step S1007. This information may be output to the user by the display unit 114 of the business risk analysis device 11, or may be output by the business risk analysis device 11 to the user terminal 12 via the network 13, and then output by the user terminal 12 to the user. The same applies to the information in Fig. 19, which will be described later.

[0129] In the example of Fig. 18, information is output in which the calculation results of the risk values ​​shown in Fig. 17 are sorted in order of risk value. That is, business risk 1901, viewpoint 1902, impact 1903, related business 1904, occurrence frequency 1905, and risk value 1906 shown in Fig. 18 correspond to business risk 1605, viewpoint 1604, impact 1606, related business 1801, occurrence frequency 1802, and risk value 1803 in Fig. 17, respectively, and this information is sorted in order of risk value 1906.

[0130] 18 may also include a comment 1907. In the example of Fig. 18, information specifying a task related to a large risk value is output as the comment 1907.

[0131] FIG. 19 is an explanatory diagram showing a second example of information output as a processing result by the business risk analysis apparatus 11 according to the embodiment of the present invention.

[0132] In the example of Fig. 19, information is output in which the calculation results of the risk values ​​shown in Fig. 17 are sorted and grouped by related business. That is, the business risk 1901 to risk value 1906 shown in Fig. 19 are the same as those shown in Fig. 18, but in Fig. 19, the information is grouped by business, and furthermore, the importance of business 2001 is added.

[0133] The importance of a task 2001 is calculated based on the risk value 1906 of each related task. For example, if the risk value of an event for each related task includes a value equal to or greater than a predetermined standard ("4" in the example of FIG. 19), the importance of the related task may be determined to be "high," and otherwise may be determined to be "medium" or "low."

[0134] As the comment 2002, information summarizing the importance of each related task may be output.

[0135] By presenting the information shown in Figure 18 or Figure 19, potential security vulnerabilities in a business can be visualized and used to propose countermeasures.

[0136] The system according to the embodiment of the present invention may be configured as follows, for example.

[0137] (1) A business risk analysis system (for example, a business risk analysis device 11 or an entire system having the functions thereof), comprising a calculation unit (for example, calculation unit 111) and a memory unit (for example, memory unit 112), wherein the memory unit holds business configuration information (for example, business configuration information 122) and occurrence probability evaluation information (for example, occurrence probability evaluation table 124), wherein the business configuration information includes information identifying the business included in the business and the components that constitute the business, and the occurrence probability evaluation information includes information associating a value indicating the probability that an information security threat will materialize in the component with a guide word that expresses the state of the component, and a value indicating the probability that a vulnerability will be exploited by a threat in the component with a guide word that expresses the state of the component. When a value indicating the probability of a threat corresponding to the actual state of a business component being realized and a value indicating the probability of a vulnerability being exploited are identified based on the guide words included in the occurrence probability evaluation information, the calculation unit calculates the frequency of an information security event occurring in the business component based on the identified values ​​(e.g., steps S1004, S3002 to S3003), calculates the occurrence frequency of an event in the business based on the occurrence frequency of the event in the component (e.g., steps S1004, S3004), and calculates a risk value for the business based on the occurrence frequency of the event and the magnitude of the impact of the event on the business (e.g., step S1006).

[0138] This allows for proper assessment of security risks in the business.

[0139] (2) In (1) above, the calculation unit calculates the frequency of occurrence of an event so that the higher the probability of a threat being realized, the higher the frequency of occurrence of the event, and the higher the probability of a vulnerability being exploited, the higher the frequency of occurrence of the event (e.g., step S3004, Figures 13A and 13B).

[0140] This allows the occurrence frequency of the event to be calculated appropriately.

[0141] (3) In (2) above, the business includes multiple tasks, the business configuration information includes information that identifies the output of the business, and the calculation unit identifies tasks related to the output of the business from the multiple tasks based on the business configuration information (e.g., step S1002), and calculates the frequency of occurrence of events for the identified related tasks (e.g., step S1004).

[0142] This allows for proper assessment of risk based on its impact on business output.

[0143] (4) In (3) above, among the multiple tasks, a task that outputs an object or information that will be the output of the business is identified as a related task, and the memory unit stores information indicating the magnitude of the impact on the business if an event occurs for each task output (e.g., impact 1606 in Figure 15), and the calculation unit calculates the business risk value so that the more frequently the event occurs, the higher the business risk value, and the greater the impact on the business if the event occurs, the higher the business risk value (e.g., step S1006, Figure 16).

[0144] This allows for an appropriate assessment of business risk based on the frequency of occurrence of events and the magnitude of their impact.

[0145] (5) In (4) above, the output of the business includes the intended output (e.g., the intended output 304) and the unintended output (e.g., the unintended output 305), and the events in the related business include at least one of the following: the stoppage of the intended output, fraud, excess and shortage, and the occurrence of the unintended output (e.g., the HAZOP guide word 1602 in Figure 15).

[0146] This allows for proper assessment of risk based on its impact on business output.

[0147] (6) In (1) above, the components of a business include business inputs (e.g., inputs 312) and at least one of people (e.g., people 314), systems, equipment (e.g., systems / equipment 315), standards, and plans (e.g., standards / plans 313) that are input into the business.

[0148] This allows for proper assessment of risk based on the components of the business.

[0149] (7) In (1) above, the business is composed of a plurality of components, and the calculation unit calculates the maximum occurrence frequency of the event in the plurality of components that make up the business as the occurrence frequency of the event in the business.

[0150] This allows appropriate assessment of the risks involved in each business operation.

[0151] (8) In the above (1), the business includes a plurality of tasks, and the calculation unit calculates the frequency of occurrence of an event for online tasks that are processed instantly among the plurality of tasks.

[0152] This allows for an appropriate assessment of business risks.

[0153] The present invention is not limited to the above-described embodiments and includes various modifications. For example, the above-described embodiments have been described in detail to provide a better understanding of the present invention, and the present invention is not necessarily limited to those including all of the described configurations. Furthermore, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of each embodiment with other configurations.

[0154] Furthermore, the above-described configurations, functions, processing units, processing means, etc. may be partially or entirely implemented in hardware, for example, by designing them as integrated circuits. The above-described configurations, functions, etc. may also be implemented in software, with a processor interpreting and executing a program that implements each function. Information such as the programs, tables, and files that implement each function can be stored in storage devices such as nonvolatile semiconductor memory, hard disk drives, and solid-state drives (SSDs), or in computer-readable, non-transitory data storage media such as IC cards, SD cards, and DVDs.

[0155] In addition, the control lines and information lines shown are those that are considered necessary for the explanation, and not all control lines and information lines in the product are necessarily shown. In reality, it can be considered that almost all components are interconnected. [Explanation of symbols]

[0156] 11 Business Risk Analysis Device 12 User terminal 13 Network 111 Arithmetic section 112 Storage section 113 Input section 114 Display section 115 Communications Department

Claims

1. A business risk analysis system, comprising: A computing unit and a storage unit are included, The storage unit holds business configuration information and occurrence probability evaluation information, the business configuration information includes information identifying the operations included in the business and the components that make up the operations, The occurrence probability evaluation information includes information that associates a value indicating the probability that a threat to information security will materialize in the component with a guide word that expresses the state of the component, and information that associates a value indicating the probability that a vulnerability will be exploited by the threat in the component with a guide word that expresses the state of the component, The calculation unit When a value indicating the probability of the threat being realized and a value indicating the probability of the vulnerability being exploited corresponding to the actual state of the business component are identified based on the guide words included in the occurrence probability evaluation information, calculate the frequency of an information security event occurring in the business component based on the identified values; calculating an occurrence frequency of the event in the business based on an occurrence frequency of the event in the component; A business risk analysis system that calculates a risk value for the business based on the frequency of occurrence of the event and the magnitude of the impact of the event on the business.

2. 2. The business risk analysis system according to claim 1, The calculation unit calculates the frequency of occurrence of the event so that the higher the probability of the threat becoming a reality, the higher the frequency of occurrence of the event, and the higher the probability of the vulnerability being exploited, the higher the frequency of occurrence of the event.

3. 3. The business risk analysis system according to claim 2, The business includes a plurality of the operations, the business configuration information includes information specifying the output of the business; The calculation unit Identifying a related business of the output of the business from the plurality of businesses based on the business configuration information; A business risk analysis system characterized by calculating the frequency with which the event occurs for the identified related business.

4. 4. The business risk analysis system according to claim 3, Among the plurality of operations, an operation that outputs an object or information that is an output of the business is identified as the related operation; the storage unit stores, for each output of the business, information indicating the magnitude of the impact on the business when the event occurs; A business risk analysis system characterized in that the calculation unit calculates the risk value of the business so that the higher the frequency of the event occurring, the higher the risk value of the business, and the greater the impact on the business if the event occurs, the higher the risk value of the business.

5. 5. The business risk analysis system according to claim 4, the outputs of the business include intended and unintended outputs; A business risk analysis system characterized in that the events in the related business include at least one of the following: suspension of the intended output, fraud, excess or shortage, and occurrence of the unintended output.

6. 2. The business risk analysis system according to claim 1, The business risk analysis system is characterized in that the components of the business include inputs to the business and at least one of people, systems, equipment, standards, and plans that are input into the business.

7. 2. The business risk analysis system according to claim 1, The business is composed of a plurality of the components, A business risk analysis system characterized in that the calculation unit calculates the maximum occurrence frequency of the event in the multiple components that make up the business as the occurrence frequency of the event in the business.

8. 2. The business risk analysis system according to claim 1, The business includes a plurality of the operations, The business risk analysis system is characterized in that the calculation unit calculates the frequency of occurrence of the event for online operations that are processed immediately among the plurality of operations.

9. A business risk analysis method executed by a business risk analysis system, The business risk analysis system includes a calculation unit and a storage unit, The storage unit holds business configuration information and occurrence probability evaluation information, the business configuration information includes information identifying the operations included in the business and the components that make up the operations, The occurrence probability evaluation information includes information that associates a value indicating the probability that a threat to information security will materialize in the component with a guide word that expresses the state of the component, and information that associates a value indicating the probability that a vulnerability will be exploited by the threat in the component with a guide word that expresses the state of the component, The business risk analysis method includes: a step in which, when a value indicating the probability of the threat being realized and a value indicating the probability of the vulnerability being exploited corresponding to the actual state of the business component are identified based on the guide words included in the occurrence probability evaluation information, the calculation unit calculates the frequency of an information security event occurring in the business component based on the identified values; a step in which the calculation unit calculates an occurrence frequency of the event in the business based on an occurrence frequency of the event in the component; a procedure in which the calculation unit calculates a risk value of the business based on the frequency of occurrence of the event and the magnitude of the impact of the event on the business.

Citation Information

Patent Citations

  • Method and system for calculating risk value of power generation enterprise information system

    CN115049192A

  • Method for evaluating risk and method for support selection of security management measures and program

    JP2005234840A

  • Server device, information management method of server device, information management program of server device, client device, information management method for client device, information management program of client device, information management system and information management method for information management system

    JP2008009878A

  • Damage calculation device, damage calculation method and damage calculation program

    JP2013225185A

  • Security measures support system

    JP2015191390A