Methods and means of analysis of risks of the information security of the enterprise
Methods and means of assessing information security risks are considered. The main problems that arise in the process of performing the analysis of the security of an enterprise in the field of information security are shown. A brief review of the existing instrumental solutions to the problems of a...
Main Authors: | , |
---|---|
Format: | Article |
Language: | English |
Published: |
Moscow Engineering Physics Institute
2017-07-01
|
Series: | Bezopasnostʹ Informacionnyh Tehnologij |
Subjects: | |
Online Access: | https://bit.mephi.ru/index.php/bit/article/view/267 |
id |
doaj-a8852667ed9548778ae54e71c1b00918 |
---|---|
record_format |
Article |
spelling |
doaj-a8852667ed9548778ae54e71c1b009182020-11-24T22:21:09ZengMoscow Engineering Physics Institute Bezopasnostʹ Informacionnyh Tehnologij2074-71282074-71362017-07-01243727710.26583/bit.2017.3.09267Methods and means of analysis of risks of the information security of the enterpriseDamir Faritovich Fayzulayev0Boris Borisovich Morozov1Astrakhan State UniversityAstrakhan State UniversityMethods and means of assessing information security risks are considered. The main problems that arise in the process of performing the analysis of the security of an enterprise in the field of information security are shown. A brief review of the existing instrumental solutions to the problems of assessing the risks of information security organizations engaged in various fields of activity is given. The main advantages and disadvantages of methods for risk assessment and software based on these techniques are analyzed. The results of the review are presented, conclusions are made regarding the shortcomings of methods and tools, and the question of the optimal correlation of such concepts as the breadth of applicability of methods and software tools and reliability, accuracy and adequacy of information security risk assessment are considered. We propose new additional stages of risk analysis that allow improving existing methods and eliminating the shortcomings identified during the review.https://bit.mephi.ru/index.php/bit/article/view/267CORASCRAMMMicrosoft Security Assessment Tool (MSAT)OCTAVERiskWatchGRIFinformation security analysisanalysis and assessment of IS risksinformation securitymethods and means of IS risk assessment |
collection |
DOAJ |
language |
English |
format |
Article |
sources |
DOAJ |
author |
Damir Faritovich Fayzulayev Boris Borisovich Morozov |
spellingShingle |
Damir Faritovich Fayzulayev Boris Borisovich Morozov Methods and means of analysis of risks of the information security of the enterprise Bezopasnostʹ Informacionnyh Tehnologij CORAS CRAMM Microsoft Security Assessment Tool (MSAT) OCTAVE RiskWatch GRIF information security analysis analysis and assessment of IS risks information security methods and means of IS risk assessment |
author_facet |
Damir Faritovich Fayzulayev Boris Borisovich Morozov |
author_sort |
Damir Faritovich Fayzulayev |
title |
Methods and means of analysis of risks of the information security of the enterprise |
title_short |
Methods and means of analysis of risks of the information security of the enterprise |
title_full |
Methods and means of analysis of risks of the information security of the enterprise |
title_fullStr |
Methods and means of analysis of risks of the information security of the enterprise |
title_full_unstemmed |
Methods and means of analysis of risks of the information security of the enterprise |
title_sort |
methods and means of analysis of risks of the information security of the enterprise |
publisher |
Moscow Engineering Physics Institute |
series |
Bezopasnostʹ Informacionnyh Tehnologij |
issn |
2074-7128 2074-7136 |
publishDate |
2017-07-01 |
description |
Methods and means of assessing information security risks are considered. The main problems that arise in the process of performing the analysis of the security of an enterprise in the field of information security are shown. A brief review of the existing instrumental solutions to the problems of assessing the risks of information security organizations engaged in various fields of activity is given. The main advantages and disadvantages of methods for risk assessment and software based on these techniques are analyzed. The results of the review are presented, conclusions are made regarding the shortcomings of methods and tools, and the question of the optimal correlation of such concepts as the breadth of applicability of methods and software tools and reliability, accuracy and adequacy of information security risk assessment are considered. We propose new additional stages of risk analysis that allow improving existing methods and eliminating the shortcomings identified during the review. |
topic |
CORAS CRAMM Microsoft Security Assessment Tool (MSAT) OCTAVE RiskWatch GRIF information security analysis analysis and assessment of IS risks information security methods and means of IS risk assessment |
url |
https://bit.mephi.ru/index.php/bit/article/view/267 |
work_keys_str_mv |
AT damirfaritovichfayzulayev methodsandmeansofanalysisofrisksoftheinformationsecurityoftheenterprise AT borisborisovichmorozov methodsandmeansofanalysisofrisksoftheinformationsecurityoftheenterprise |
_version_ |
1725771883432902656 |