发明名称 INFORMATION TECHNOLOGY RISK MANAGEMENT SYSTEM AND METHOD THEREFOR
摘要 PROBLEM TO BE SOLVED: To provide an information technology risk management system and method for maximizing consulting efficiency.SOLUTION: An information technology risk management method includes; a control database construction process S100 for defining and storing one control item, a control action and a control-categorized performer and observant from each control element; a current situation analysis process S200 for analyzing the current situations of an organization control maturity; an asset evaluation process S300 for evaluating the identification and significance of information asset to be managed; a risk evaluation process S400 for extracting the brittle point of the control element, and for evaluating a risk on the basis of a correlation relation between the control elements and an information asset and threat; a risk processing process S500 for selecting the control elements for risk relaxation by determining the control guarantee standard of a risk, and for establishing a risk processing plan, and for revising a policy; and a control execution process S600 for executing the management examination of a manager for the risk processing plan, and for generating a report related with the applicability of an internal control structure and an international/domestic standard, and for executing user education for control execution.
申请公布号 JP2011018360(A) 申请公布日期 2011.01.27
申请号 JP20100211370 申请日期 2010.09.21
申请人 METARISK INC 发明人 LEE HYOUNG WON
分类号 G06Q10/00;G06Q10/06;G06Q50/00 主分类号 G06Q10/00
代理机构 代理人
主权项
地址