发明名称 A SECURITY ASSESSMENT METHOD FOR USE BY SECURITY AND CIP PROFESSIONALS
摘要 A method and software system for Security and CIP Professionals (CIP) that addresses the shortcomings in today's Critical Infrastructure Protection (CIP) methods, and offers a new security assessment methodology equipped to meet the present challenges of CIP, as well as future challenges. The method is based on an End-to-End Security Assessment (EESA) that provides a wide examination of system information flows. The method disclosed is for implementing end-to-end security assessment (EESA) for use by Security and CIP professionals for large, complex, critical infrastructure (LCCI) systems. The first step of the method is determining security policy and sensitivity levels of data. Further steps include identifying and analyzing critical business-derived information flows for the layers, security mechanisms, formats and communications protocols of the system; assessing each of said information flows for security gaps; determining the risk level of each of said information flows by applying a formula that takes into account the threat, its likelihood and its potential impact on the system; comparing the required defence levels to said security mechanisms, listing all gaps found according to a prioritization process that determines the urgency of closing each gap and creating a detailed list of the prioritized gaps; and offering specific countermeasures to close each of said gaps, wherein emphasis is put on optimizing said countermeasures.
申请公布号 WO2007072483(A3) 申请公布日期 2009.04.09
申请号 WO2006IL01462 申请日期 2006.12.19
申请人 ADAR, EYAL 发明人 ADAR, EYAL
分类号 G06F12/14;G08B23/00 主分类号 G06F12/14
代理机构 代理人
主权项
地址