Business Process Status-Based Risk Analysis

LI Bing,WANG Shengyuan,BAO Xuhua,SHA Hailiang
DOI: https://doi.org/10.3321/j.issn:1000-0054.2009.z2.012
2009-01-01
Abstract:An information security risk assessment method was developed to accurately measure information securlty risks using business process state analysis.The method defines the key performance indicator of the business process (the process period) as the risk scale, so changes in the process period indicate the risk.The occurrence of threads affects the operation of the information system, eventually resulting in state transitions of business process/activities hosted by the information system.The changes in the process period(i.e., risk)are obtained by analyzing the state transitions.Therefore, information security risk calculation is converted into solving for changes of the business process period.Test using this algorithm show that the influence of threats to the information svstem on the business system can be calculated, thereby confirming the accuracy and validity of the algorithm.
What problem does this paper attempt to address?