RAMEX - A PROTOTYPE EXPERT-SYSTEM FOR COMPUTER SECURITY RISK ANALYSIS AND MANAGEMENT

被引:10
作者
KAILAY, MP [1 ]
JARRATT, P [1 ]
机构
[1] UNIV BIRMINGHAM,SCH COMP SCI,BIRMINGHAM B15 2TT,W MIDLANDS,ENGLAND
关键词
RISK ANALYSIS; RISK MANAGEMENT; INTENTIONAL THREATS; INFORMATION CLASSIFICATION; VULNERABILITIES; COUNTERMEASURES; BUSINESS IMPACT ASSESSMENT; EXPERT SYSTEM;
D O I
10.1016/0167-4048(95)00013-X
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information security is emerging as the business risk of the 90s for many commercial organizations. The commercia sector should recognise the need for a structured approach to security assessment in the form of risk analysis. This paper describes the development of RAMeX, a qualitative based prototype expert system designed for small to medium-sized commercial organizations.
引用
收藏
页码:449 / 463
页数:15
相关论文
共 31 条
  • [1] ANDERSON AM, 1991, 7TH P IFIP INT C INF, P301
  • [2] Baker R., 1991, COMPUTER SECURITY HD
  • [3] BENNETT SP, 1992, 8TH P IEEE ANN COMP, P64
  • [4] BODEAU DJ, 1992, 8TH P IEEE ANN COMP, P56
  • [5] BREWER M, 1992, INFORMATION SECURITY
  • [6] CARROLL JM, 1984, MANAGING RISK COMPUT
  • [7] CLARK R, 1989, 4TH P IFIP INT COMP, P421
  • [8] CORNWALL H, 1990, DATA THEFT
  • [9] ELBRA RA, 1992, COMPUTER SECURITY HD
  • [10] EVANS D, 1993, COMPUTER WEEKLY 0527