发明名称 IT RISK MANAGEMENT SYSTEM AND IT RISK MANAGEMENT METHOD USING THE SYSTEM
摘要 <P>PROBLEM TO BE SOLVED: To provide an IT risk management system for maximizing the efficiency of consultation. <P>SOLUTION: An IT risk management system comprises: a control master database section that decomposes a control policy including a plurality of control items, a plurality of control actions, a performer and observant of each control into control elements, and stores each data associating with each other; a policy management section that displays the data; a risk scenario management section that extracts a vulnerable point from the data included in the control element and displays the vulnerable point associating with the control element, an information asset and a threat; a level management section that, on the basis of a PDCA cycle, displays existence of each control action, maturity of the control action, and a level of control compliance of each performer to the set compliance control; a risk countermeasure section that displays decision-making support data using the control compliance level; and a control operation management section that displays data contributing to a control operation instruction and management on the basis of the control compliance level. <P>COPYRIGHT: (C)2013,JPO&INPIT
申请公布号 JP2013050969(A) 申请公布日期 2013.03.14
申请号 JP20120228641 申请日期 2012.10.16
申请人 METARISK INC 发明人 LEE HYOUNG WON
分类号 G06Q10/00;G06Q10/06;G06Q50/00 主分类号 G06Q10/00
代理机构 代理人
主权项
地址