Sécurité informatique pour la gestion des risques

Add to my library

SE2500 V3 Archive

Sécurité informatique pour la gestion des risques

Author : Frédérique VALLÉE

Publication date: April 10, 2016, Review date: September 2, 2020 | Lire en français

Add to my library Add to my library

Logo Techniques de l'Ingenieur You do not have access to this resource.
Request your free trial access! Free trial

Already subscribed?

Overview

ABSTRACT

Information systems are today currently used in almost all companies. The software security of these systems must protect them against numerous threats of various origins. Risk analysis can determine, depending on the system's vulnerability, each of its threats criticality. It allows then to propose necessary and sufficient solutions to mitigate the risks at an acceptable level. This paper introduces first the notion of software risk and focuses then on risk analysis methods used for information systems and on some solutions of risk mitigation. In conclusion an overview of the main standards used for cybersecurity is given.

Read this article from a comprehensive knowledge base, updated and supplemented with articles reviewed by scientific committees.

Read the article

AUTHOR

  • Frédérique VALLÉE : Associate Professor of Mathematics - Doctor of Statistics - Expert in dependability of programmed systems - Associate Director of All4tec, Massy, France

 INTRODUCTION

The safety of a system corresponds to the non-occurrence of events that could diminish or damage the integrity of the system and its environment, throughout the duration of the system's activity, whether successful, degraded or failed. Security covers both random (danger) and deliberate (threat) events.

For more than a quarter of a century, virtually all sectors of activity, both industrial and service, have had to rely on high-level safety systems. These systems, which also have to be developed at the lowest possible cost, are often at the frontiers of technological knowledge and have little feedback from experience. Achieving these two sometimes contradictory goals requires not only the use of specific tools, but also the rigorous implementation of an organization adapted to the objectives sought.

At the same time, software has gradually taken on a dominant role in on-board systems and in so-called control-command systems: it's software that starts or brakes cars, it's software that regulates electricity distribution in the national grid, it's software that dispatches calls in large telephone exchanges, and it's software that controls automated manufacturing in factories. There are even plans to entrust it with the entire operation of autonomous vehicles.

Since the advent of office automation, software has also been at the heart of the information system that no company can do without today. Today, this system enables companies to harmoniously manage customers, purchasing, production, accounting, personnel, and so on. In recent years, the spread of the Internet has further accentuated and complicated this relationship of dependence between the company and its information system.

Whether their main function is administrative or technical, programmed systems can, if they malfunction or are inadequately protected, cause human, material or economic disasters of varying scale.

As computer technology is quite different from other technologies, it soon became clear that specific techniques were needed to manage the risks associated with these systems.

In particular, this article distinguishes between the issues and methods used for information systems and for scientific and technical programmed systems. It then focuses on the techniques used for information systems, while aspects relating to scientific and technical programmed systems are covered in another article [SE 2 501]...

You do not have access to this resource.
Logo Techniques de l'Ingenieur

Exclusive to subscribers. 97% yet to be discovered!

You do not have access to this resource. Click here to request your free trial access!

Already subscribed?


KEYWORDS

Information technology   |   Risk analysis   |   informations systems security   |   information technology risks

EDITIONS

Other editions of this article are available:

Ongoing reading
Sécurité informatique pour la gestion des risques

Article included in this offer

"Security of information systems"

( 92 articles )

Complete knowledge base

Updated and enriched with articles validated by our scientific committees

Services

A set of exclusive tools to complement the resources

View offer details

Dans les ressources documentaires

Sécurité de l’information, cybersécurité et protection des données de vie privée - NF EN ISO/IEC 27001 : 2023

La sécurité de l'information fait partie du périmètre de la normalisation (ISO et AFNOR). À savoir les no...

NIS2 et ISO/IEC 27001 – Vers une cyberrésilience de l’Union européenne

L'objet de cet article est d’apporter des précisions sur la directive NIS2, les différences avec la norme...

Social engineering et sécurité du système d’information - De la nécessité de la prévention

Nous présentons les mécanismes d’attaque liés au social engineering , tels que les techniques de  p...

Cyberespionnage : la menace APT

Cet article propose de faire le point sur les attaques informatiques « APT », acronyme internat...

Tous les livres blancs
Toutes les actualités
Contact us