首页> 外文会议>Foundations of security analysis and design VI : FOSAD tutorial lectures >A Method for Security Governance, Risk, and Compliance (GRC): A Goal-Process Approach
【24h】

A Method for Security Governance, Risk, and Compliance (GRC): A Goal-Process Approach

机译:一种安全治理,风险与合规性(GRC)的方法:目标过程方法

获取原文
获取原文并翻译 | 示例

摘要

The Governance, Risk, and Compliance (GRC) management process for Information Security is a necessity for any software systems where important information is collected, processed, and used. To this extent, many standards for security managements at operational level exists (e.g., ITIL, ISO27K family etc). What is often missing is a process to govern security at organizational level.In this tutorial, we present a method to analyze and design security controls that capture the organizational setting of the system and where business goals and processes are the main citizen. The SI*-GRC method is a comprehensive method that is composed of i) a modeling framework based on a requirement engineering framework, with some extensions related to security & GRC concerns, such as: trust, permission, risk, and treatment, 2) a analysis process defining systematical steps in analyzing and design security controls, 3) analytical techniques to verify that certain security properties are satisfied and the risk level is acceptable, and at last 4) a CASE tool, namely the SI* Tool to support analysts in using the method.To illustrate this method, we use a running example on e-Health adapted from a real-life process in an hospital partner.
机译:对于收集,处理和使用重要信息的任何软件系统,信息安全的治理,风险和合规性(GRC)管理过程都是必不可少的。在此程度上,存在许多用于操作级别的安全管理标准(例如ITIL,ISO27K系列等)。通常缺少在组织级别上管理安全性的过程。在本教程中,我们提供一种分析和设计安全性控件的方法,这些控件可以捕获系统的组织设置以及业务目标和流程是主要公民的位置。 SI * -GRC方法是一种综合方法,包括:i)基于需求工程框架的建模框架,并具有与安全和GRC相关的一些扩展,例如:信任,许可,风险和处理,2)一个分析过程,定义了分析和设计安全控制措施中的系统步骤; 3)分析技术以验证某些安全属性得到满足并且风险水平可以接受,最后是4)CASE工具,即SI *工具,可为分析人员提供支持为了说明这种方法,我们使用了一个运行在电子卫生系统上的示例,该示例是根据医院合作伙伴的实际流程改编而成的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号