09-12-2016 дата публикации
Номер: KR1020160141457A
Автор:
RYU, JE HONG,
LEE, HONG HAN,
PARK, KI JUN,
PARK, KOAN HEE,
HWANG, IN JUN,
AN, SEUNG HOON
Принадлежит:
The present invention relates to a risk assessment system for an information security management system. More specifically, the risk assessment system for an information security management system comprises: a threat classification providing module to provide an assessment score for each threat which is classified into a large classification of a general threat, an identification/approval threat, a confidentiality threat, an integrity threat, an availability threat, a denial threat, an access control threat, a service reliability threat, and a personal threat for a consultant device, and a plurality of detail classifications included in the large classification; a risk analysis module to receive an asset importance score for assets in a range of an information security management system, a weak point for each classified threat, and an assessment score for the weak point from the consultant device; and a risk assessment module to use the assessment score for each threat and the received ...
Подробнее