发明名称 Information security audit method
摘要 An information security audit method and system is provided. A normalized weighting of each of a plurality of members of an organization is computed according to a level and at least one feature, such as member attribute, asset, performance etc. of each of the members. A plurality of risk evaluation values corresponding to a plurality of audit items are computed and a normalized risk evaluation value of each of the members is further computed according to the risk evaluation values and the normalized weighting. A relation of the normalized risk evaluation value and a plurality of threshold value intervals are determined to dynamically adjust an audit period and/or a number of the audit items according to the relation. Alternatively a relation of risk evaluation values and a plurality of threshold value intervals are determined.
申请公布号 GB2507598(A) 申请公布日期 2014.05.07
申请号 GB20120021598 申请日期 2012.11.30
申请人 INSTITUTE FOR INFORMATION INDUSTRY 发明人 CHIEN-TING KUO;HE-MING RUAN;CHIN-LAUNG LEI
分类号 G06Q10/06;G06F21/50 主分类号 G06Q10/06
代理机构 代理人
主权项
地址