| Diversification of vulnerabilities and frequent security incidents make improving the security of the system imminent. Information security is dependent on the integrate system engineering involving technology and management. Then risk assessment is important in the system engineering and the precondition of information security. Risk assessment is a process that identifying the weaknesses of the information system, analysing the threat level of events which use these weakness, evaluating the possibility of negative impacts for the threats. The specification for risk assessment to implement is not specific enough, so it is necessary to refine related theory according to actual further.This work of this paper are as follows: 1, According to the GB/T 20984-2007 standard " Information Security Technology and Information System Risk Assessment Specification", design the evaluation form, improve the risk assessment model and risk assessment model, making the standard implementation. 2, According to the detailed risk assessment standard and the implementation process of risk assessment, analyse the demand of the risk assessment system, design and implement the system to verify its effectiveness of the model and method.It provides security basis for information systems to plan and run, with the tool designed and developed to assess the electronic government affairs information system, drawn the risk assessment conclusion for the system, based on GB/T 20984-2007 standard in th is article.According to the result of risk assessment, taking necessary measures, will be reduced to an acceptable level of risk, and maintain the level of risk. Strengthen e-government network border protection ability, perfect the electronic government affairs information security system, to ensure the safety of e-government information as a whole. Finally, the follow-up work of this thesis is discussed. |