一种新的信息安全风险评估方法:八度快板

Emine Serap Kurt, Aysun Yaşar, Kenan Terzioğlu, S. Demirkıran
{"title":"一种新的信息安全风险评估方法:八度快板","authors":"Emine Serap Kurt, Aysun Yaşar, Kenan Terzioğlu, S. Demirkıran","doi":"10.36880/c14.02624","DOIUrl":null,"url":null,"abstract":"Information system risk assessment, an essential aspect of information security management, assists organizations in identifying and analyzing critical information system assets and reducing potential risks. Internal control and risk management are two systems that complement each other in controlling an organization's activities. As a result, internal control activities, critical for controlling and managing risks, should be carried out with a risk focus. Institutions should first analyze the risks that may emerge in business processes before evaluating the steps that should be taken to secure their information assets. Many risk assessment methods are complicated and expensive, and qualified professionals should only carry them out. The OCTAVE Allegro method is a comprehensive assessment of an organization's operational risk environment to get better results without requiring considerable risk assessment information. Risk assessment can be completed in a short period and at a low cost using this method, and the effectiveness of internal control can be improved. The study's objective is to give information about the OCTAVE Allegro method, which can help prevent the risks of ensuring information security as information technologies advance and explain the method's application areas.","PeriodicalId":130191,"journal":{"name":"International Conference on Eurasian Economies 2022","volume":"16 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"A New Generation Method for Assessing Information Security Risks: OCTAVE Allegro\",\"authors\":\"Emine Serap Kurt, Aysun Yaşar, Kenan Terzioğlu, S. Demirkıran\",\"doi\":\"10.36880/c14.02624\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Information system risk assessment, an essential aspect of information security management, assists organizations in identifying and analyzing critical information system assets and reducing potential risks. Internal control and risk management are two systems that complement each other in controlling an organization's activities. As a result, internal control activities, critical for controlling and managing risks, should be carried out with a risk focus. Institutions should first analyze the risks that may emerge in business processes before evaluating the steps that should be taken to secure their information assets. Many risk assessment methods are complicated and expensive, and qualified professionals should only carry them out. The OCTAVE Allegro method is a comprehensive assessment of an organization's operational risk environment to get better results without requiring considerable risk assessment information. Risk assessment can be completed in a short period and at a low cost using this method, and the effectiveness of internal control can be improved. The study's objective is to give information about the OCTAVE Allegro method, which can help prevent the risks of ensuring information security as information technologies advance and explain the method's application areas.\",\"PeriodicalId\":130191,\"journal\":{\"name\":\"International Conference on Eurasian Economies 2022\",\"volume\":\"16 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-09-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Conference on Eurasian Economies 2022\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.36880/c14.02624\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Conference on Eurasian Economies 2022","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.36880/c14.02624","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

信息系统风险评估是信息安全管理的一个重要方面,它可以帮助组织识别和分析关键信息系统资产,降低潜在风险。内部控制和风险管理是控制组织活动的两个相辅相成的系统。因此,对于控制和管理风险至关重要的内部控制活动应该以风险为重点进行。机构应首先分析业务流程中可能出现的风险,然后再评估为保护其信息资产而应采取的步骤。许多风险评估方法复杂且昂贵,只有合格的专业人员才能执行。OCTAVE Allegro方法是对组织的操作风险环境进行全面评估,在不需要大量风险评估信息的情况下获得更好的结果。采用该方法可以在较短的时间内以较低的成本完成风险评估,提高内部控制的有效性。该研究的目的是提供有关OCTAVE快板方法的信息,这可以帮助防止信息技术进步带来的信息安全风险,并解释该方法的应用领域。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A New Generation Method for Assessing Information Security Risks: OCTAVE Allegro
Information system risk assessment, an essential aspect of information security management, assists organizations in identifying and analyzing critical information system assets and reducing potential risks. Internal control and risk management are two systems that complement each other in controlling an organization's activities. As a result, internal control activities, critical for controlling and managing risks, should be carried out with a risk focus. Institutions should first analyze the risks that may emerge in business processes before evaluating the steps that should be taken to secure their information assets. Many risk assessment methods are complicated and expensive, and qualified professionals should only carry them out. The OCTAVE Allegro method is a comprehensive assessment of an organization's operational risk environment to get better results without requiring considerable risk assessment information. Risk assessment can be completed in a short period and at a low cost using this method, and the effectiveness of internal control can be improved. The study's objective is to give information about the OCTAVE Allegro method, which can help prevent the risks of ensuring information security as information technologies advance and explain the method's application areas.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信