« » , 08, 2006 1629
-
-, . - , -.
-, . - , -.
- . . -, , -, 2002 . , , ISO17799, BS7799, ISO27001, -. .
, , , -, CORAS [1], OCTAVE (www.cert.org/octave) CRAMM (www.cramm.com). , -. , , -, , BS7799 ISO17799, -, . , .
-
coras. CORAS [1] Information Society Technologies. , , Event-Tree-Analysis, , HazOp FMECA [1].
CORAS UML / AS/NZS 4360: 1999 Risk Management ISO/IEC 17799-1: 2000 Code of Practie for Information Security Management. , ISO/IEC TR 13335-1: 2001 Guidelines for the Management of IT Security IEC 61508: 2000 Functional Safety of Electrical/Electronic/Programmable Safety Related.
CORAS , , , . Windows- Java- [6].
OCTAVE. OCTAVE (Operationally Critical Threat, Asset and Vulnerability Evaluation) — . OCTAVE:
- ;
- ;
- , ;
- , .
OCTAVE , , . , OCTAVE-S . , OCTAVE.
CRAMM. CRAMM (CCTA Risk Analysis and Management Method) 1985 , . CRAMM, , , «».
CRAMM . . CRAMM . , CRAMM. , Siemens CRAMM Expert CRAMM Express.
- , - , , . - COBIT (www.isaca.org/cobit).
COBIT (Control Objectives for Information and Related Technologies) , -, . - COBIT - « ».
COBIT -, , . , OCTAVE , COBIT . . , . , , , . COBIT, , . , (.. ), . , , .
|
| - |
. + ; – ; ? .
- , . - . - , . , OCTAVE.
- Bjorn, A.G. (January 2002). CORAS, A Platform for Risk Analysis on Security Critical Systems — Model-based Risk Analysis Targeting Security (www.nr.no/coras)
- Alberts, C.J. & Dorofee, A.J. (June 2001). OCTAVE Method Implementation Guide Version 2.0. Carnegie Mellon University (www.cert.org/octave/omig.html)
- Alberts, C.J. & Dorofee, A.J. (June 2002). Managing Information Security Risks — The OCTAVE Approach. Pearson Education Ltd.
- Model Based Security Risk Analysis for Web Applications:The CORAS Approach. EuroWeb2002.
- Insight Consulting. (2003). CRAMM Expert Walkthrough and Overview — Flash Presentation.
- CORAS Tool 2.0 (coras.sourceforge.net/downloads.html).
(apastoev@kerberus.ru) — «» ().
COBIT
- — . , , , -.
- — . , — .
- — , , , , .
- — , , «» - .
- — , .
- — , , .
- — . , .
- — , , , .
- T- — , - . — , , , — .
- — , - ..
- - — , , (), , .
- — , , , , .
- — -, , , , .
- — -, .
- – , , , , , .
- — , , «», «», «» .
- — .
- — , .
- — , , , , .
- — (, Internet-).
- — .
- — . , , , , , .
- — . , , .








