论文部分内容阅读
伴随信息化的不断发展,各种各样的电脑病毒对企业信息系统的攻击频率也逐渐升高,能做出反应的时间越来越短,企业信息安全已经不能被传统的事后式和被动式保证,风险管理的思想应该被企业构建到信息系统里面。企业进行信息安全风险管理项目时,安全不能百分之百地得到保证,所以要根据成本的效益原则,整合企业的各种资源进行有效利用。
With the continuous development of information technology, the attack frequency of various computer viruses on enterprise information systems is gradually increasing, and the response time is getting shorter and shorter. The enterprise information security can no longer be traditionally ex post and passive guarantees , The idea of risk management should be built into the information system by the enterprise. When enterprises carry out the information security risk management project, the security can not be guaranteed 100%. Therefore, according to the principle of cost-effectiveness, the various resources of the enterprise should be integrated and utilized effectively.