Development of a Method for Comprehensive Evaluation of the Service Provision Quality
摘要
The analysis of international regulators showed that the key point of information security (IS) management principles is risk assessment. In fact, risk is an integral assessment of how effectively the available defenses are able to resist information attacks. Practice shows that today two main groups of security risk assessment methods can be clearly distinguished. The first group of methods allows you to establish the level of risk by assessing the degree of compliance with a defined set of requirements for ensuring information security. The second group of IS risk assessment methods is based on determining the probability of attacks, as well as their damage levels. For the evaluation of the complex performance indicator, reference tables were developed, which allow to distinguish the ranges of changes of the necessary parameters and to determine them in conditional points. This simple method makes it possible to obtain fairly adequate evaluation results, and in addition, to combine them with the results of accurate calculations for individual specific parameters.