The risk factors for information security and its assessment process are analyzed completely.According to the characteristic of uncertainty information in the assessment process
the reasoning algorithm on Bayesian Networks is presented
and the conditional probability matrix of the reasoning rule is given base on the expert knowledge.Thus
the model of information security risk assessment is constructed.Finally
an instance of the risk assessment approach on the model is analyzed
which demonstrates the rationality and feasibility of this method.So it provides a new method for information security assessment.