Return
An efficient security data-driven approach for implementing risk assessment
DOI:10.1016/j.jisa.2020.102593.png)
Abstract
En 中文
Information security implementation in an organization regardless of its business processes will not be effective. Current approaches to risk assessment have moved towards business process-oriented ones. Thus, in new approaches, assets are got attention based on the business processes involved. But existing approaches that are based on business processes have their drawbacks. For example, we need to detail processes to know what security data is produced or used in tasks, and what are their importance from the organization's point of view. Security data certainly has different meanings. How security data moves in an organization's network environment is another important point. Therefore, the main task in information security would be protecting security data, from the point of creation location to storage. In this paper, several improvements over other solutions are presented. The business processes of the organization are categorized according to security concerns (called fear stories). In the next improvement, we have gone one step further in the business processes, which is extracting the organization's security data. Therefore, security data plays a key role in our model. The next improvement is the introduction of the security data life cycle (creation, edit, display, process, transfer, store), and its adaptation to the asset layers (logical, physical, and human) through a series of predefined patterns. Thus, in this model, a multi-organization pyramid of security needs will be formed, each pyramid being a hierarchical multi-layer, involving security concerns, related business processes, extracted security data, assets involved, identified risks and optimal combination of security controls. At the end of the paper, we will show how the model presented in this paper will effectively improve the popular risk assessment methods such as CVSS (Common Vulnerability Scoring System) and OWASP (Open Web Application Security Project).
Keywords:
Risk assessment
Business process
Security data
Vulnerability
Threat
CVSS
OWASP
Security concerns
Security requirement
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
IF:
3.7
Papers:
1.9K
Citations:
4.9K

