×

You are using an outdated browser Internet Explorer. It does not support some functions of the site.

Recommend that you install one of the following browsers: Firefox, Opera or Chrome.

Contacts:

+7 961 270-60-01
ivdon3@bk.ru

  • Assessment of information risks based on expert information (for example, SBHI AR "Medical prevention center")

    Now risks associated with the violation of information security properties become especially relevant, including for medical institutions. This article describes the technique of assessment of information risks, including the algorithm of assessment of the acceptable risk, fuzzy cognitive model and the algorithm of expert assessment of the current risks. The proposed model and algorithm of assessment of current risks allows defining of multiple points that characterize the current level of information risks on a coordinate plane "damage - probability". The main difference between the described method and already existent ones – is determination of asset significance for company that allows making reasonable management decisions in the end. The offered technique has been applied in the state budgetary healthcare institution of Astrakhan region "Medical prevention center": curve of acceptable risk is constructed; the current (relevant) information risks are estimated. Then results of assessment were used for making management decisions on lowering the risks to acceptable values.

    Keywords: assessment of information risks, acceptable risk, current risk, fuzzy cognitive model, information asset, expert information, medical prevention center

  • Formalization of concepts of acceptable and tolerant risk

    Risk management process represents the complex problem possessing a number of specific features. Ambiguity of the concept "risk" and variety of manifestations of risk and opportunities of overcoming of its adverse effects are aggravated with that the most part of the parameters participating in process of development of managing decisions have no accurate (numerical) characteristics. Estimates of the majority of concepts are formulated by experts in a verbal form. For overcoming of the specified difficulties in work the method of a numerical assessment of levels of the acceptable is offered and tolerant is risk. The entered metrics allow to start formalization of process of search and acceptance of optimum management decisions for reduction of value of the current risk to the target objective. The offered mathematical model can be the basis for the corresponding software for the purpose of creation of system of decision support in the sphere of a risk management.

    Keywords: risk management, acceptable risk, tolerant risk, current risk level, degree of danger of a situation