The Risk Assessment and Improvement of City Card Information System
|School||Xi'an University of Electronic Science and Technology|
|Course||Management Science and Engineering|
|Keywords||City Card System Risk assessment information system security OCTAVE|
With computer technology, communication technology and the rapid development of Internet technology, social information process is picking up speed. To meet the new global digital existence and the competitive environment, city card will be included in the construction schedule of each country. Establishment of city card information security system has now become the important task of today’s city card security building. The risk assessment as an important part of information security management plays an important role in various stages of information security management system construction. Risk assessment is a comprehensive evaluation process, and the establishment of streamlined and effective assessment of the risk assessment model is the basis for successful completion.Through the analysis of international and domestic advanced security model and risk assessment methods, we find suitable risk assessment methods and means for city card information system. Based on the characteristics of city cards system, we make hierarchical decomposition of the system, and finally get an abstract description of the various risk factors of the system, and build a city card system risk assessment model based on OCTAVE. According to the four relationship of the asset value, threat, vulnerability and preventive measures of the card information system, we select an appropriate risk calculation method, and calculate system risk assessment value of the city card information system.At last, risk assessment model is used in the city card information system, and draw the risk rating of it. Some risk improvement strategies are proposed according to the assessment result.