| The rapid development of new generation information and communication technology brings great convenience to social production and life,but also brings unprecedented network security risks.X Electric Power Company is the operator of electric power infrastructure.X Electric Power Material-Cloud Platform is the core system to support the operation of power network.Scientific and timely discovery of network security risks faced by the system and building a comprehensive network security risk management system are of great significance to ensure system security,power network security and even national security.This paper takes X Power Company’s Material-Linked Cloud Platform as the research object,and refers to project risk management and network security risk assessment theory,studies its network security risk management.First,through the theoretical research on network security,project risk management and security risk assessment,the risk assessment model and risk analysis method used in this paper are clarified.Then,it investigates and analyses the project overview and safety management status of X Power Company’s Material-Linked Cloud Platform,and identifies 31 types of risk factors in combination with assets,threats and vulnerability risks.Then,use expert judgment method and ALE multiplier method to assess the risk,through the comprehensive judgment of the risk value,four categories and ten categories of network security risks are obtained,among which sensitive data leakage,hacker intrusion into the cloud service and malicious software attack are the main security risks.Finally,according to the risk response principles and strategies,comprehensive economic costs and control effectiveness,put forward risk response measures.From the perspective of life cycle,this paper puts forward the construction methods of network security risk management system,and provides guidance for the establishment of dynamic risk management system.The research results of this paper have practical operation value for risk avoidance of X Power Company,and can strengthen the overall security risk defense ability of the enterprise.In addition,the research results of this paper can provide reference value for the network security risk management and protection system design in the construction of power Internet of Things and new power system,and also provide typical cases and theoretical exploration for the network security risk assessment in China. |