1. GB/T 20984-2007,Information security technology— Risk assessment specification for information security. National Standardization Management Committee, Beijing (2007)
2. NIST-800-30, Special Publications Risk Management Guide. National Institute of Standards and Technology (2006)
3. Hong, F.: Information Security Risk Assessment Guide. The State Council informatization office, Beijing (2004)
4. Zhang, L., Xiang, D.Q.: Grey evaluation model and algorithm of security effectiveness of military information system. Journal of Air Force Engineering University: Natural Science Edition 8(1), 77–80 (2007)
5. Duan, J.L., Zhang, Q.S., Liu, W.J.: The model of information system’s risk assessment based on analytic hierarchy process and grey theory. Journal of Guang-dong University of Technology 23(4), 12–16 (2006)