首页> 外文会议>International Conference on Industrial Engineering and Engineering Management(IEamp;EM'2005); 20051106-08; Chongqing(CN) >A BUSINESS PROCESS-BASED METHOD ON SECURITY REQUIREMENTS ANALYSIS OF INFORMATION SYSTEMS
【24h】

A BUSINESS PROCESS-BASED METHOD ON SECURITY REQUIREMENTS ANALYSIS OF INFORMATION SYSTEMS

机译:基于业务过程的信息系统安全需求分析方法

获取原文
获取原文并翻译 | 示例

摘要

The analysis of security requirements is the important premise and basis of security management. As the change of the background and task of information systems, the asset-based risk analysis methods come out to be out of place. A business process-based security requirements analysis method is put forward. A tri-layer information systems model is established to be the basis and the communication platform of security requirement analysis. The primary security requirements can be listed through analyzing the security requirements of business processes. A concept of risk packet and a risk transferring model are brought forward to facilitate the risk analysis of assets of information systems. Then, a coverage analysis method is used to check whether all kinds of risk of assets are satisfied by the primary security requirements. If some kinds of risk can't be covered by the primary requirements, supplementary requirements will be needed to form the final security requirements list. This method, which aims to protect the security operations of business processes supported by information systems, has strong objective and can facilitate the engineering applications of security management.
机译:安全需求的分析是安全管理的重要前提和基础。随着信息系统背景和任务的变化,基于资产的风险分析方法逐渐出现。提出了一种基于业务流程的安全需求分析方法。建立了三层信息系统模型作为安全需求分析的基础和交流平台。可以通过分析业务流程的安全要求来列出主要的安全要求。提出了风险包的概念和风险转移模型,以方便信息系统资产的风险分析。然后,使用覆盖率分析方法来检查主要安全要求是否满足各种资产风险。如果主要需求无法涵盖某些风险,则需要补充需求以形成最终的安全需求清单。该方法旨在保护信息系统支持的业务流程的安全操作,具有很强的目标性,可以促进安全管理的工程应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号