信息安全研究 ›› 2018, Vol. 4 ›› Issue (10): 946-953.

• 风险评估专题 • 上一篇    下一篇

信息安全风险评估服务资质认证发现

王笑1,成林芳2,翟亚红1   

  1. 1. 中国网络安全审查技术与认证中心
    2. 湖南省电子信息产业研究院
  • 收稿日期:2018-10-11 出版日期:2018-10-15 发布日期:2018-10-11
  • 通讯作者: 王笑
  • 作者简介:王笑 工学学士,主要研究领域信息安全管理、信息安全风险评估技术 成林芳 硕士研究生,主要研究领域信息安全管理、信息安全攻防及渗透测试技术 翟亚红 工程硕士,高级工程师,主要研究领域信息安全管理、信息安全服务能力认证技术

Analysis of Information Security Risk Assessment Service Qualification Certification Found

  • Received:2018-10-11 Online:2018-10-15 Published:2018-10-11

摘要: 摘要对于对外提供信息安全风险评估服务的组织来说,通过信息安全风险评估服务资质认证是体现其技术与管理能力的重要方式.中国网络安全审查技术与认证中心在对外开展风险评估服务资质认证过程中,发现大多数组织在实施风险评估项目的过程中往往存在缺乏依据、不够客观、说服性不足等问题,在风险评估结果输出时,往往偏重于各种图表及计算模型的罗列,而缺乏相应的文字解释说明.将对发现的问题进行说明,同时基于风险评估工作实践给出问题解决和处理思路,推动信息安全风险评估技术实践及标准不断完善,提高信息安全风险评估服务能力.

关键词: 风险评估, 服务资质认证, 信息安全风险评估服务能力, 计算模型, 风险评估技术实践

Abstract: For organizations that provide information security risk assessment services to the outside world, certification of information security risk assessment service qualification is an important way to embody their technical and management capabilities. During the process of qualification certification for risk assessment services, our center found that most units often lack the basis, objectivity and persuasiveness in the implementation of risk assessment. When the risk assessment results are exported, they tend to focus on various charts and calculation models. This paper will explain the problems found, and based on the practice of risk assessment, give the idea of problem solving and handling, promote the practice and standards of information security risk assessment technology to improve constantly, and improve the level of information security risk assessment service capacity building.

Key words: risk assessment, service qualification authentication, information security risk assessment service capability, calculation models, the practice and standards of information security risk assessment technology