论文标题
法医就好风险管理概念
Forensic-Ready Risk Management Concepts
论文作者
论文摘要
当前,存在许多方法,支持法医准备的实施以及间接使用法医就业软件系统。但是,方法中使用的术语及其重点往往会有所不同。为了促进法医就绪的软件系统的设计,需要确定基本概念的清晰度,以便可以明确地制定和评估其要求。当将法医准备作为信息安全性附加过程时,这一点尤其重要。在本文中,根据六种现有方法得出和对齐与法医准备有关的概念。然后,结果是通过法医准备增强信息系统安全风险管理(ISSRM)的垫脚石。
Currently, numerous approaches exist supporting the implementation of forensic readiness and, indirectly, forensic-ready software systems. However, the terminology used in the approaches and their focus tends to vary. To facilitate the design of forensic-ready software systems, the clarity of the underlying concepts needs to be established so that their requirements can be unambiguously formulated and assessed. This is especially important when considering forensic readiness as an add-on to information security. In this paper, the concepts relevant to forensic readiness are derived and aligned based on six existing approaches. The results then serve as a stepping stone for enhancing Information Systems Security Risk Management (ISSRM) with forensic readiness.