{"title":"关键基础设施保护(CIP)挑战的风险管理,最佳实践和工具","authors":"E. Adar, A. Wuchner","doi":"10.1109/IWCIP.2005.18","DOIUrl":null,"url":null,"abstract":"Risk management (RM) has become increasingly important in dealing with information and IT security over the past several years. This article aims at discussing the major challenges facing critical infrastructure protection (CIP) RM, and outlines several methods and best practice guidelines that can be used to cope with it, including: creating a RM framework and RM measurement criteria; usage of advanced risk analysis (RA) methods, and adoption of CIP models that can be used for RA; and development and implementation of RM tools. Use of RM tools can play a major role in this process, as it can raise the efficiency of RM activities, and decrease reliance on any individual RA specialist's knowledge. The contribution of such tools is even greater, when dealing with critical infrastructures; as it is very difficult for a single specialist to cope with the diversity and complexity of CIP risk assessment.","PeriodicalId":393991,"journal":{"name":"First IEEE International Workshop on Critical Infrastructure Protection (IWCIP'05)","volume":"116 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-11-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"27","resultStr":"{\"title\":\"Risk management for critical infrastructure protection (CIP) challenges, best practices & tools\",\"authors\":\"E. Adar, A. Wuchner\",\"doi\":\"10.1109/IWCIP.2005.18\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Risk management (RM) has become increasingly important in dealing with information and IT security over the past several years. This article aims at discussing the major challenges facing critical infrastructure protection (CIP) RM, and outlines several methods and best practice guidelines that can be used to cope with it, including: creating a RM framework and RM measurement criteria; usage of advanced risk analysis (RA) methods, and adoption of CIP models that can be used for RA; and development and implementation of RM tools. Use of RM tools can play a major role in this process, as it can raise the efficiency of RM activities, and decrease reliance on any individual RA specialist's knowledge. The contribution of such tools is even greater, when dealing with critical infrastructures; as it is very difficult for a single specialist to cope with the diversity and complexity of CIP risk assessment.\",\"PeriodicalId\":393991,\"journal\":{\"name\":\"First IEEE International Workshop on Critical Infrastructure Protection (IWCIP'05)\",\"volume\":\"116 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2005-11-03\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"27\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"First IEEE International Workshop on Critical Infrastructure Protection (IWCIP'05)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/IWCIP.2005.18\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"First IEEE International Workshop on Critical Infrastructure Protection (IWCIP'05)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IWCIP.2005.18","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Risk management for critical infrastructure protection (CIP) challenges, best practices & tools
Risk management (RM) has become increasingly important in dealing with information and IT security over the past several years. This article aims at discussing the major challenges facing critical infrastructure protection (CIP) RM, and outlines several methods and best practice guidelines that can be used to cope with it, including: creating a RM framework and RM measurement criteria; usage of advanced risk analysis (RA) methods, and adoption of CIP models that can be used for RA; and development and implementation of RM tools. Use of RM tools can play a major role in this process, as it can raise the efficiency of RM activities, and decrease reliance on any individual RA specialist's knowledge. The contribution of such tools is even greater, when dealing with critical infrastructures; as it is very difficult for a single specialist to cope with the diversity and complexity of CIP risk assessment.