Abstract. Traditional information technology (IT) security risk assessment approaches are based on an analysis of events, probabilities and impacts. In practice, security experts often find it difficult to determine IT risks reliably with precision. In this paper, we review the risk determination steps of traditional risk assessment approaches and report on our experience of using such approaches. Our experience is based on performing IT audits and IT business insurance cover assessments within a reinsurance company. The paper concludes with a summary of issues concerning traditional approaches that are related to the identification and evaluation of events, probabilities and impacts. We also conclude that there is a need to develop alternative approaches, and suggest a security requirements-based risk assessment approach without events and probabilities.
This paper indicates the importance of classified management of components in view of different functions of plant components, presents the principles based on which Third Qinshan Nuclear Power Plant (TQNPP) implements the classified management of components, and introduces the concept of SPV component in nuclear power stations. It focus on expounding the analysis and identification of SPV systems and components, explaining the methods to determine the list of SPV key systems and to evaluate the system priority sequence; getting the SPV fault tree of the system and SPV points; classification for the SPV points, finding the SPV component chain. The management requirements and practice for SPV components are discussed from different viewpoints of component management.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.