信息安全风险模型 Security Risk Model of Information System 范雯 FAN Wen 1 first-author 武汉大学国际软件学院,湖北,武汉,430072 武汉大学国际软件学院,湖北,武汉,430072 International School of Software,Wuhan University International School of Software,Wuhan University 基于决策分析技术,提出了一种决策驱动的风险管理模型框架,并给出了安全策略纯效益的算法,该模型与目前国内流行的风险模型相比,能定量的分析风险管理,给出有害事件爆发频率和影响程度的具体缩减值以及计算出每个安全策略的纯效益,得到最佳安全策略. According to Decision Analysis technique,propose a framework of decision driven risk management model,and an equation for net benefit of security policy.Compared to other security risk models,this model can quantitative analyze risk management,calculate the reduction in frequency and consequences of bad events,especially it can calculate every security policy’s net benefit,and then give out the best policy. 年损失期望 效用函数 决策分析技术 annual lost expectancy(ALE) utility function decision analysis TP309 2005-01-01 2021-04-01 S2