RiskPatrol: A risk management system considering the integration risk management with business continuity processes

被引:16
作者
Cha, Shi-Cho [1 ]
Juo, Pei-Wen [1 ]
Liu, Li-Ting [1 ]
Chen, Wei-Ning [1 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Dept Informat Management, Taipei 106, Taiwan
来源
ISI 2008: 2008 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS | 2008年
关键词
business continuity management; disaster recovery; emergency response; risk management;
D O I
10.1109/ISI.2008.4565039
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Both business continuity management (BCM) and risk management (RM) processes are very important to current organizations. The former ensures that the organizations have the ability to limit losses in the events of severe contingencies or disasters. The latter helps organizations identify potential security incidents and adopt cost-effective countermeasures to the incidents. However, current risk management approaches or methodologies usually ignore the different focuses about risks in RM processes and BCM processes. Therefore, even though an organization has established its RM processes, it may need to re-assess the risks for BCM processes. In light of this, we propose a risk management system, called RiskPatrol, to provide an integrative vie,,v about risks for RM and BCM processes. RiskPatrol provides an easy way for people to retain enough information for BCM while they do risk assessment in RM process, and vice versa. As the redundant risk assessment work in RM and BCM processes can be reduced, our system can hopefully contribute to overcome the deficiencies of current risk management approaches.
引用
收藏
页码:110 / +
页数:2
相关论文
共 28 条
  • [1] ANDERSON AM, 1991, P IFIP TC11 7 INT C, P301
  • [2] [Anonymous], 2004, ENTERPRISE RISK MANA
  • [3] [Anonymous], 2002, Managing Information Security Risks: The OCTAVE Approach
  • [4] [Anonymous], 2002, QUALITATIVE RISK ANA
  • [5] [Anonymous], 2002, NIST SPECIAL PUBLICA
  • [6] [Anonymous], 2005, 177992005 ISOIEC
  • [7] *BSI, 2003, PAS56 BSI
  • [8] *BSI, 2006, 2599912006 BSI
  • [9] *BSI, 2006, 779932006 BSI
  • [10] Cha SC, 2005, INT FED INFO PROC, V191, P1