发明名称 OBJECT-ORIENTED METHOD, SYSTEM AND MEDIUM FOR RISK MANAGEMENT BY CREATING INTER-DEPENDENCY BETWEEN OBJECTS, CRITERIA AND METRICS
摘要 A method, system, and medium for assessing and/or managing risks for an organization is described. The method, for example, comprises the steps of inventorying a number of assets of the organization, identifying at least one criterion defining a security objective of the organization, and identifying one or more inventoried assets that relate to the identified criterion. The assets may include one or more inventoried assets that relate to the identified criterion. The assets may include one or more computers, networking equipment therefor and physical locations where the computers and networking equipment are located. The method may also include the step of formulating one or more metric equations, each metric equation being defined, in part, by the one or more identified assets. Each metric equation yields an outcome value when one or more measurements are made relating to the identified assets. The method may also include the step of assessing the risk to the organization based on the measured values of the one or more metric equations. Corresponding system, medium and means are also described.
申请公布号 WO02054325(A2) 申请公布日期 2002.07.11
申请号 WO2002US00110 申请日期 2002.01.02
申请人 TRUSECURE CORPORATION 发明人 LOVEJOY, KRISTIN, GALLINA;CROSS, PATRICK, IVO;TIPPETT, PETER, S.
分类号 G06Q40/00;H04L29/06;(IPC1-7):G06F17/60 主分类号 G06Q40/00
代理机构 代理人
主权项
地址