New Approach for Information Security Evaluation and Management of IT Systems in Educational Institu

来源 :上海交通大学学报(英文版) | 被引量 : 0次 | 上传用户:gaga1235
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Security evaluation and management has become increasingly important for Web-based information technology(IT)systems,especially for educational institutions.For the security evaluation and management of IT systems in educational institutions,determining the security level for a single IT system has been well developed.However,it is still difficult to evaluate the information security level of the entire educational institution consid-ering multiple IT systems,because there might be too many different IT systems in one institution,educational institutions can be very different,and there is no standard model or method to provide a justifiable information security evaluation among different educational institutions considering their differences.In light of these diffi-culties,a security evaluation model of educational institutions'IT systems(SEMEIS)is proposed in this work to facilitate the information security management for the educational institutions.Firstly,a simplified educational industry information system security level protection rating(EIISSLPR)with a new weight redistribution strategy for a single IT system is proposed by choosing important evaluation questions from EIISSLPR and redistributing the weights of these questions.Then for the entire educational institution,analytic hierarchy process(AHP)is used to redistribute the weights of multiple IT systems at different security levels.Considering the risk of pos-sible network security vulnerabilities,a risk index is formulated by weighting different factors,normalized by a utility function,and calculated with the real data collected from the institutions under the evaluation.Finally,the information security performance of educational institutions is obtained as the final score from SEMEIS.The results show that SEMEIS can evaluate the security level of the education institutions practically and provide an efficient and effective management tool for the information security management.
其他文献
目的探讨血站在无偿献血宣传、动员和招募过程中,运用全社会精神文明建设运行机制,采取相应的工作措施,促进无偿献血事业的科学发展。方法1)无偿献血传播社会文明新风尚。无
期刊
生产性粉尘作业危害程度的调查孟关海,李乾正(杭州市机械工业局医疗卫生协作组)报道:根据国家标准《生产性粉尘作业危害程度分级》(GB5817-86),对19家企业进行了分级调查,结果为776个粉尘作业点中,0级
目的了解豫东地区大学生无偿献血情况,及时调整宣传方向。方法利用穿越软件对商丘市中心血站2004~2011无偿献血的档案信息进行分类比较和分析。结果2004~2011年在校大学生献血
目的调查广州市民对重大事故发生后紧急招募的响应情况。方法分别收集“6·29”广州油罐车爆炸事故发生前后3d广州市街头6个固定献血站自愿无偿献血者的资料并进行分析比对。
问:2004年8月18日,省医保中心发布了《关于强化医疗保险定点医疗服务管理有关问题的通知》,对参保人员门诊、住院、大额检诊与用药费用审批及严厉查处违规医疗行为等提出新
卫生部要求自2006年9月30日起,取消机采血小板的采集的交通误工补助。为保证临床需求,本中心多措并举,实现平稳过渡。
会议
无偿献血从其产生和发展历程都具有明显的公共管理色彩,无偿献血是一项涉及面广、政策性强的群众性系统工程,离不开政府的高度重视、卫生行政部门的尽职尽责、社会各界和广大
Do you want your wedding to be special?If your answer is yes,look no further than Lan Feng.如果你想要一个特别的婚礼,那么就去找蓝枫吧! Do you want your wedding
随着美国民主党热门总统竞选人贝拉克·奥巴马的人气扶摇直上,他的夫人米歇尔·奥巴马也逐渐成为舆论关注的焦点人物。 With the popular popularity of Barack Obama, the