从信息安全风险评估的原理和研究现状入手,提出了基于层次分析法(AHP)和模糊综合评判的信息安全风险评估的方法,解决了风险评估中定性指标定量评估的难点。最后给出实例,证明该方法能有效地应用于信息安全风险评估。
This article starts with the theory and research of information security risk assessment.h proposes information security risk assessment method based on Analytic Hierarchy Process(AHP) and fuzzy comprehensive evaluation.It solves the difficulty when conducting quantitative evaluation of qualitative assessment in risk assessment.Finally it gives a practical example to prove that this method can be applied very well to information security risk assessment.