发明名称 INFORMATION ASSET RISK DEGREE EVALUATION SYSTEM
摘要 <p><P>PROBLEM TO BE SOLVED: To provide a system for evaluating the degree of risk of enterprise information assets, enabling the execution of a risk assessment job without sufficient expertise. <P>SOLUTION: Characteristics in the information assets are represented in four fields, namely, information asset type, confidentiality significance, integrity significance, and availability significance. Each measure to be taken thereto is described in a detailed content field. An information security common criterion master having these fields is prepared in advance. Then, by four field values registered in an information asset ledger table describing the characteristics of the information assets, the information security common criterion master is retrieved. The contents in the detailed content field described in a record obtained by this retrieval become the entire measures to be performed for the information assets concerned. Namely, if only values can be written in the four fields of the information asset ledger table, necessary measures can be determined without expertise on information security. <P>COPYRIGHT: (C)2009,JPO&INPIT</p>
申请公布号 JP2009104478(A) 申请公布日期 2009.05.14
申请号 JP20070276917 申请日期 2007.10.24
申请人 RICOH CO LTD 发明人 SHIMAMURA TAKASHI;HIROTA MARI;CHINO SHINICHI
分类号 G06Q10/00;G06Q10/06;G06Q50/00 主分类号 G06Q10/00
代理机构 代理人
主权项
地址