首页> 外文会议>2011 Fifth International Conference on Research Challenges in Information Science >A Model-Driven engineering approach with diagnosis of non-conformance of security objectives in business process models
【24h】

A Model-Driven engineering approach with diagnosis of non-conformance of security objectives in business process models

机译:一种模型驱动的工程方法,可诊断业务流程模型中的安全目标是否不合格

获取原文

摘要

Several reports indicate that the highest business priorities include: business improvement, security, and IT management. The importance of security and risk management is gaining that even government statements in some cases have imposed the inclusion of security and risk management within business management. Risk assessment has become an essential mechanism for business security analysts, since it allows the identification and evaluation of any threats, vulnerabilities, and risks to which organizations maybe be exposed. In this work, a framework based on the concepts of Model-Driven Development has been proposed. The framework provides different stages which range from a high abstraction level to an executable level. The main contribution lie in the presentation of an extension of a business process meta-model which includes risk information based on standard approaches. The meta-model provides necessary characteristics for the risk assessment of business process models at an abstract level of the approach. The framework has been equipped with specific stages for the automatic validation of business processes using model-based diagnosis which permits the detection of the non-conformance of security objectives specified. The validation stages ensure that business processes are correct with regard to the objectives specified by the customer before they are transformed into executable processes.
机译:几份报告表明,最高的业务优先级包括:业务改进,安全性和IT管理。安全和风险管理的重要性正在日益提高,甚至在某些情况下,即使政府声明也已将安全和风险管理纳入了业务管理范围。风险评估已成为业务安全分析人员的基本机制,因为它可以识别和评估组织可能面临的任何威胁,漏洞和风险。在这项工作中,提出了一个基于模型驱动开发概念的框架。该框架提供了从高抽象级别到可执行级别的不同阶段。主要贡献在于表示业务流程元模型的扩展,该模型包括基于标准方法的风险信息。元模型为方法的抽象级别上的业务流程模型的风险评估提供了必要的特征。该框架配备了特定的阶段,可以使用基于模型的诊断来自动验证业务流程,从而可以检测到所指定的安全目标是否不合格。验证阶段可确保业务流程在转换为可执行流程之前,对于客户指定的目标而言是正确的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号