The method of analysis of data-processing risks optimized by level ( Marion ) is a method of audit, suggested since 1983 by CLUSIF, aiming at evaluating the data-processing security level of a company. The objective is double:
- to locate the audited company compared to a level considered to be correct, and the level reached by the similar companies
- to identify the threats and vulnerabilities to be countered.
Principles
Six topics
The analysis is articulated in 6 broad topics:
- organisational safety
- physical safety
- the continuity of service
- the data-processing organization
- logical safety and the exploitation
- the safety of the
applications
Twenty-seven indicators
The indicators, distributed in these 6 topics, will be evaluated, and developed on a scale of 0 (very unsatisfactory) to 4 (very satisfactory), level 3 being the level considered to be correct. Each indicator is affected of a weight according to its importance.
Seventeen types of threats
- physical Accidents
- physical Malveillance
- Panne of IF
- Deficiency of personnel
- Deficiency of person receiving benefits
- Interruption of operation of the network
- Error of seizure
- Error of transmission
- Error of exploitation
- Error of design/development
- Latent defect of a software package
- Embezzlement
- Diversion of goods
- illicit Copy of software
- Indiscretion/diversion of information
- immaterial Sabotage
- logical Attack of the network
Phases
Evolution
Method MARION did not evolve/move any more since 1998.
The CLUSIF proposes from now on a harmonized Méthode of analysis of the risks (Méhari) which one can think that it will replace MARION.
Appendices
See too