摘要
安全评估是指依据多个安全相关指标对复杂信息系统进行评价的过程。为提高信息安全风险评估的客观性和准确性,文章提出利用粗糙集相关理论进行安全评估的方法,并详细阐述了该方法的原理及运用它进行安全评估的基本流程,最后将评估结论落实到安全等级划分中的做法具有较好的现实意义和较强的可操作性。
Information Security risk evaluation is the process of evaluating complex information systems according to multi-guideline. In order to raise the objectivity and accuracy of the evaluation, an evaluation method based on Rough Set is proposed, the principle and basic procedure of evaluation by this method is described in detail. Finally, it is of realistic and practical significance to apply the evaluation conclusion mentioned above to security-level classification.
出处
《信息安全与通信保密》
2007年第10期89-91,共3页
Information Security and Communications Privacy
关键词
粗糙集
安全评估
等级划分
rough set
security evaluation
classification