首页> 外文会议>2017 IEEE International Conference on Systems, Man, and Cybernetics >A multi-perspective methodology for evaluating the security maturity of data centers
【24h】

A multi-perspective methodology for evaluating the security maturity of data centers

机译:评估数据中心安全成熟度的多角度方法

获取原文
获取原文并翻译 | 示例

摘要

Threats to information security can have great impact on business finances and company's reputation. Traditional methodologies for evaluating the maturity of data centers investigate security parameters to determine the compliance of data centers and international security norms. This paper proposes two innovative evaluation procedures to capture other security perspectives on data center environments: (1) weighted analysis - it weights higher security controls simultaneously present in a higher number of norms; (2) it is sensitive to the importance level that the organization assigns to each security control. Through the proposed methodology, security engineers can identify security issues, characterize the security maturity, and suggest new policies improve security configurations of data centers. This paper also includes a case study to evaluate the benefits of the methodology in real-world scenarios. Results demonstrated that the proposed methodology evaluates higher the security elements more relevant for the company, where as traditional approaches consider all security aspects to be equally important.
机译:信息安全威胁会严重影响企业财务和公司声誉。评估数据中心成熟度的传统方法研究安全性参数,以确定数据中心的合规性和国际安全规范。本文提出了两种创新的评估程序,以捕获关于数据中心环境的其他安全性观点:(1)加权分析-加权以更高数量的规范同时出现的更高安全性控制; (2)对组织分配给每个安全控制的重要性级别敏感。通过提出的方法,安全工程师可以识别安全问题,表征安全成熟度并提出新的策略来改善数据中心的安全配置。本文还包括一个案例研究,以评估该方法在实际场景中的优势。结果表明,所提出的方法对与公司更相关的安全元素进行了更高的评估,而传统方法认为所有安全方面都同等重要。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号