返回
An efficient security data-driven approach for implementing risk assessment
DOI:10.1016/j.jisa.2020.102593.png)
摘要
En 中文
Information security implementation in an organization regardless of its business processes will not be effective. Current approaches to risk assessment have moved towards business process-oriented ones. Thus, in new approaches, assets are got attention based on the business processes involved. But existing approaches that are based on business processes have their drawbacks. For example, we need to detail processes to know what security data is produced or used in tasks, and what are their importance from the organization's point of view. Security data certainly has different meanings. How security data moves in an organization's network environment is another important point. Therefore, the main task in information security would be protecting security data, from the point of creation location to storage. In this paper, several improvements over other solutions are presented. The business processes of the organization are categorized according to security concerns (called fear stories). In the next improvement, we have gone one step further in the business processes, which is extracting the organization's security data. Therefore, security data plays a key role in our model. The next improvement is the introduction of the security data life cycle (creation, edit, display, process, transfer, store), and its adaptation to the asset layers (logical, physical, and human) through a series of predefined patterns. Thus, in this model, a multi-organization pyramid of security needs will be formed, each pyramid being a hierarchical multi-layer, involving security concerns, related business processes, extracted security data, assets involved, identified risks and optimal combination of security controls. At the end of the paper, we will show how the model presented in this paper will effectively improve the popular risk assessment methods such as CVSS (Common Vulnerability Scoring System) and OWASP (Open Web Application Security Project).
Keyword:
Risk assessment
Business process
Security data
Vulnerability
Threat
CVSS
OWASP
Security concerns
Security requirement
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.7
论文数:
2.0K
被引数:
4.9K
机构
引用论文
More than the individual: Examining the relationship between culture and Information Security Awareness
COMPUTERS & SECURITY
IF5.4

