The invention discloses an
information system security
risk assessment method. The method includes the steps of constructing a threatening behavior model
bank, matching calling behaviors recorded in an
information system with threatening behaviors in the threatening behavior model
bank to obtain decision values of the matched calling behaviors, determining weighted values of the threatening behaviors according to the decision values of the matched calling behaviors, and enabling the weighted values of the threatening behaviors to be combined with a
vulnerability weighted value and a remedial measure weighted value to obtain a risk grade. The invention further discloses an
information system security
risk assessment device. Through the scheme of the information
system security
risk assessment method and device, security risks of the information
system can be measured in multi-dimensional mode, the defects of existing
risk evaluation quantification are greatly made up for, the accuracy and credibility of
threat evaluation are improved, and the core problem of
risk quantification of the information
system can be solved; consequently, users can conveniently and objectively know the condition of running risks of the information system, and the risks of the information system can be perceived.