科研院所安全信息系统节点风险评价研究
2021-02-28惠建新娄洪伟乔德志
惠建新 娄洪伟 乔德志







摘 要:风险对组织及其资产存在破坏的可能性,它是安全评估的重要因素之一。文章采用定性分析与定量分析相结合的方法进行风险评估,在确定评价对象的基础上,建立一种基于知识的定性分析法,提出风险等级设定和风险防范措施,实践运行证明,该评价体系具有安全性高、稳定性好、易操作、高可靠等优势,可极大提高风险评估效率。
关键词:节点风险;信息安全;系统网络测评
中图分类号:TP39 文献标识码:A文章编号:2096-4706(2021)16-0153-05
Research on Node Risk Assessment of Security Information System in Scientific Research Institutes
HUI Jianxin1, LOU Hongwei2, QIAO Dezhi3
(1.Purple Mountain Observatory, Chinese Academy of Sciences, Nanjing 210023, China; 2.Changchun Institute of Optics, Fine Mechanics and Physics, Chinese Academy of Sciences, Changchun 130033, China; 3.Dalian Institute of Chemical Physics, Chinese Academy of Sciences, Dalian 116023, China)
Abstract: Risk has the possibility of damage to the organization and its assets, which is one of the important factors of safety assessment. In this paper, it is the combination use of qualitative analysis and quantitative analysis for risk assessment. On the basis of determining the evaluation object, a knowledge-based qualitative analysis method is established, and the risk level setting and risk prevention measures are put forward. The practical operation shows that the evaluation system has the advantages of high security, good stability, easy operation and high reliability, which can greatly improve the efficiency of risk assessment.
Keywords: node risk; information security; system network evaluation
0 引 言
经过多年的系统改造工作,大部分安全项目承研单位的安全信息系统都配置了必要的安全产品,建立了安全策略以及系统内相关的风险管制目标和针对每种节点风险评价所采取的各种控制措施。
然而,安全信息系统的节点风险评价缺失,目前普遍采用的方法是根据信息系统资产、脆弱性和威胁各要素最终赋值结果进行风险计算,存在不确定信息难以量化的问题,掩盖了资产要素对保密性、完整性和可用性的不同需求,导致参与计算的脆弱性要素存在重复计算问题,而且评估结果太过依赖专家的主观性判断,对最终结果造成干擾。
安全网络的节点管理不等同于网络系统管理。应用安全网以服务科研相关的安全工作需要切实了解在此过程中相关的资产。这里的资产包括对组织或相应任务有价值的所有事件,包括涉密网信息系统软硬件设备、存储的文件和数据等。……
