发明名称 METHOD, SYSTEM, AND COMPUTER PROGRAM PRODUCT FOR ASSESSING INFORMATION SECURITY
摘要 <p>A method, system and computer program product for assessing information security interviews regarding technical and non-technical issues. In an embodiment, users are interviewed (302) based on areas of expertise. In an embodiment, information security assessments are performed on domains within an enterprise, the results of which are rolled-up to perform an information security assessment across the enterprise. The invention optionally includes application specific questions (1402) and vulnerabilities and/or industry specific questions (1402) and vulnerabilities. The invention optionally permits users to query a repository of expert knowledge. The invention optionally provides users with working aids (1412). The invention optionally permits users to execute third party testing/diagnostic applications. The invention optionally combines results of executed third party testing/diagnostic applications with user responses to interview questions (1402), to assess information security. A system in accordance with the invention includes an inference engine (304), which may include a logic based inference engine, a knowledge based inference engine, and/or an artificial intelligence inference engine. In an embodiment, the invention includes an application specific tailoring tool that allows a user to tailor the system to assess security of information handled by a third party application program.</p>
申请公布号 WO2001082205(A1) 申请公布日期 2001.11.01
申请号 US2001040600 申请日期 2001.04.26
申请人 发明人
分类号 主分类号
代理机构 代理人
主权项
地址