首页> 外文会议>IEEE International Conference on Application of Information and Communication Technologies >Towards integration of risk-driven and evidence-driven information security measurement
【24h】

Towards integration of risk-driven and evidence-driven information security measurement

机译:致力于整合风险驱动和证据驱动的信息安全度量

获取原文

摘要

Carefully designed information security metrics enable informed and effective decision making. However, the current state of the art of developing security metrics is not sufficiently advanced. A major challenge is that typically the risk-driven (top-down modelling) and evidence-driven (bottom-up monitoring) metrics approaches are not aligned, and often used separately. Consequently, it is not possible to understand the impact of monitored evidence to actual security risk. A crosscut model for risk-driven and evidence-driven security metrology is needed. We analyze the concepts needed to be able to integrate these two main approaches.
机译:精心设计的信息安全指标可实现明智且有效的决策。但是,开发安全度量标准的当前技术水平还不够先进。一个主要的挑战是,通常风险驱动(自上而下的建模)和证据驱动(自下而上的监视)度量方法是不一致的,并且经常分开使用。因此,不可能了解受监视的证据对实际安全风险的影响。需要用于风险驱动和证据驱动的安全度量的横切模型。我们分析了能够集成这两种主要方法所需的概念。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号