arrow
返回

An efficient security data-driven approach for implementing risk assessment

delete2020-10-01
delete12
PRE
AI
A
Alireza Shameli‐Sendi *
DOI:10.1016/j.jisa.2020.102593delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Information security implementation in an organization regardless of its business processes will not be effective. Current approaches to risk assessment have moved towards business process-oriented ones. Thus, in new approaches, assets are got attention based on the business processes involved. But existing approaches that are based on business processes have their drawbacks. For example, we need to detail processes to know what security data is produced or used in tasks, and what are their importance from the organization's point of view. Security data certainly has different meanings. How security data moves in an organization's network environment is another important point. Therefore, the main task in information security would be protecting security data, from the point of creation location to storage. In this paper, several improvements over other solutions are presented. The business processes of the organization are categorized according to security concerns (called fear stories). In the next improvement, we have gone one step further in the business processes, which is extracting the organization's security data. Therefore, security data plays a key role in our model. The next improvement is the introduction of the security data life cycle (creation, edit, display, process, transfer, store), and its adaptation to the asset layers (logical, physical, and human) through a series of predefined patterns. Thus, in this model, a multi-organization pyramid of security needs will be formed, each pyramid being a hierarchical multi-layer, involving security concerns, related business processes, extracted security data, assets involved, identified risks and optimal combination of security controls. At the end of the paper, we will show how the model presented in this paper will effectively improve the popular risk assessment methods such as CVSS (Common Vulnerability Scoring System) and OWASP (Open Web Application Security Project).
Keyword:
Risk assessment
Business process
Security data
Vulnerability
Threat
CVSS
OWASP
Security concerns
Security requirement
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
2.0K
被引数:
4.9K

机构

S
Shahid Beheshti University
学者数:
7.6K
论文数: 6.8K
被引数: 6.9K
引用论文

引用论文

Incorporation of the sodium channel of lobster nerve into artificial liposomes
err1977-11-01
err0
PREAI
errRaimundo Villegas; Gloria M. Villegas; Flor V. Barnola; Efraim Racker
err分享
err收藏
T RAINING P ARAMEDICS : E MERGENCY C ARE FOR C HILDREN WITH S PECIAL H EALTH C ARE N EEDS
err2009-07-02
err0
PREAI
errDaniel W. Spaite; Katherine J. Karriker; Marsha Seng; Carol Conroy; Norma Battaglia; Mark Tibbitts; Ronald M. Salik
err分享
err收藏
err分享
err收藏
Oxidative Stress and Free-Radical Oxidation in BCG Granulomatosis Development
err2013-01-01
err0
errOAAI
errElena Menshchikova; Nikolay Zenkov; Victor Tkachev; Oksana Potapova; Liliya Cherdantseva; Vyacheslav Shkurupiy
err分享
err收藏
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
err分享
err收藏
学者 查看更多内容