« » , 08, 2006 1629

-

-, . - , -.

-, . - , -.

- . . -, , -, 2002 . , , ISO17799, BS7799, ISO27001, -. .

, , , -, CORAS [1], OCTAVE (www.cert.org/octave) CRAMM (www.cramm.com). , -. , , -, , BS7799 ISO17799, -, . , .

 

-

coras. CORAS [1] Information Society Technologies. , , Event-Tree-Analysis, , HazOp FMECA [1].

CORAS UML / AS/NZS 4360: 1999 Risk Management ISO/IEC 17799-1: 2000 Code of Practie for Information Security Management. , ISO/IEC TR 13335-1: 2001 Guidelines for the Management of IT Security IEC 61508: 2000 Functional Safety of Electrical/Electronic/Programmable Safety Related.

CORAS , , , . Windows- Java- [6].

OCTAVE. OCTAVE (Operationally Critical Threat, Asset and Vulnerability Evaluation) — . OCTAVE:

  • ;
  • ;
  • , ;
  • , .

OCTAVE , , . , OCTAVE-S . , OCTAVE.

CRAMM. CRAMM (CCTA Risk Analysis and Management Method) 1985 , . CRAMM, , , «».

CRAMM . . CRAMM . , CRAMM. , Siemens CRAMM Expert CRAMM Express.

 

- , - , , . - COBIT (www.isaca.org/cobit).

COBIT (Control Objectives for Information and Related Technologies) , -, . - COBIT - « ».

COBIT -, , . , OCTAVE , COBIT . . , . , , , . COBIT, , . , (.. ), . , , .

-

. + ; – ; ? .

- , . - . - , . , OCTAVE.

  1. Bjorn, A.G. (January 2002). CORAS, A Platform for Risk Analysis on Security Critical Systems — Model-based Risk Analysis Targeting Security (www.nr.no/coras)
  2. Alberts, C.J. & Dorofee, A.J. (June 2001). OCTAVE Method Implementation Guide Version 2.0. Carnegie Mellon University (www.cert.org/octave/omig.html)
  3. Alberts, C.J. & Dorofee, A.J. (June 2002). Managing Information Security Risks — The OCTAVE Approach. Pearson Education Ltd.
  4. Model Based Security Risk Analysis for Web Applications:The CORAS Approach. EuroWeb2002.
  5. Insight Consulting. (2003). CRAMM Expert Walkthrough and Overview — Flash Presentation.
  6. CORAS Tool 2.0 (coras.sourceforge.net/downloads.html).

(apastoev@kerberus.ru) — «» ().


 

COBIT

  • — . , , , -.
  • — . , — .
  • — , , , , .
  • — , , «» - .

  • — , .
  • — , , .
  • — . , .
  • — , , , .
  • T- — , - . — , , , — .
  • — , - ..
  • - — , , (), , .

  • — , , , , .
  • — -, , , , .
  • — -, .

  • – , , , , , .
  • — , , «», «», «» .

  • — .
  • — , .
  • — , , , , .
  • — (, Internet-).

  • — .
  • — . , , , , , .
  • — . , , .
1 2


26/04/2012 03


« »

:

« »

c