首页> 外文会议>International conference on business process management >Improvement of Security Costs Evaluation Process by Using Data Automatically Captured from BPMN and EPC Models
【24h】

Improvement of Security Costs Evaluation Process by Using Data Automatically Captured from BPMN and EPC Models

机译:通过使用从BPMN和EPC模型自动捕获的数据来改进安全成本评估过程

获取原文

摘要

Amount of security breaches and organizations' losses, related to them, is increasing every year. One of the key reasons is a high dependency of organization's key business processes on information and information technology. To decrease the risk of possible breaches, organizations have to ensure "due diligence" and "due care" principles. This means, organizations need to apply requirements or controls defined by existing security standards. One of the main issues in such approach is identification of critical areas and evaluation of cost for security requirements implementation. In this paper we consider how our previously proposed method for information security requirements implementation cost evaluation could be linked with organizations' business processes. Our proposal could help us identify organization critical areas, which need to be protected and could let us to calculate security costs, related to the protected areas.
机译:与他们相关的安全违规和组织损失的金额每年都在增加。其中一个主要原因是组织对信息和信息技术的关键业务流程的高度依赖性。为了减少可能违规的风险,组织必须确保“尽职调查”和“适当关注”原则。这意味着,组织需要应用现有安全标准定义的要求或控制。这种方法中的主要问题之一是确定关键领域和安全要求实施成本的评估。在本文中,我们考虑我们先前提出的信息安全要求实施成本评估的方法如何与组织的业务流程相关联。我们的提案可以帮助我们确定需要受保护的组织关键领域,并可以让我们计算与受保护区相关的安全成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号