RAMEX - A PROTOTYPE EXPERT-SYSTEM FOR COMPUTER SECURITY RISK ANALYSIS AND MANAGEMENT

被引:11
作者
KAILAY, MP [1 ]
JARRATT, P [1 ]
机构
[1] UNIV BIRMINGHAM,SCH COMP SCI,BIRMINGHAM B15 2TT,W MIDLANDS,ENGLAND
关键词
RISK ANALYSIS; RISK MANAGEMENT; INTENTIONAL THREATS; INFORMATION CLASSIFICATION; VULNERABILITIES; COUNTERMEASURES; BUSINESS IMPACT ASSESSMENT; EXPERT SYSTEM;
D O I
10.1016/0167-4048(95)00013-X
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information security is emerging as the business risk of the 90s for many commercial organizations. The commercia sector should recognise the need for a structured approach to security assessment in the form of risk analysis. This paper describes the development of RAMeX, a qualitative based prototype expert system designed for small to medium-sized commercial organizations.
引用
收藏
页码:449 / 463
页数:15
相关论文
共 31 条
[1]  
ANDERSON AM, 1991, 7TH P IFIP INT C INF, P301
[2]  
Baker R., 1991, COMPUTER SECURITY HD
[3]  
BENNETT SP, 1992, 8TH P IEEE ANN COMP, P64
[4]  
BODEAU DJ, 1992, 8TH P IEEE ANN COMP, P56
[5]  
BREWER M, 1992, INFORMATION SECURITY
[6]  
CARROLL JM, 1984, MANAGING RISK COMPUT
[7]  
CLARK R, 1989, 4TH P IFIP INT COMP, P421
[8]  
CORNWALL H, 1990, DATA THEFT
[9]  
ELBRA RA, 1992, COMPUTER SECURITY HD
[10]  
EVANS D, 1993, COMPUTER WEEKLY 0527