首页> 外文会议>IEEE International Conference on Application of Information and Communication Technologies >Towards integration of risk-driven and evidence-driven information security measurement
【24h】

Towards integration of risk-driven and evidence-driven information security measurement

机译:跨越风险驱动和证据驱动信息安全测量的整合

获取原文

摘要

Carefully designed information security metrics enable informed and effective decision making. However, the current state of the art of developing security metrics is not sufficiently advanced. A major challenge is that typically the risk-driven (top-down modelling) and evidence-driven (bottom-up monitoring) metrics approaches are not aligned, and often used separately. Consequently, it is not possible to understand the impact of monitored evidence to actual security risk. A crosscut model for risk-driven and evidence-driven security metrology is needed. We analyze the concepts needed to be able to integrate these two main approaches.
机译:精心设计的信息安全度量能够提供通知和有效的决策。 然而,发展安全指标的当前状态不足以高达。 主要挑战是通常,风险驱动(自上而下建模)和证据驱动(自下而上监测)度量方法未对齐,并且通常单独使用。 因此,不可能了解监控证据对实际安全风险的影响。 需要用于风险驱动和证据驱动的安全计量的横切模型。 我们分析了能够整合这两种主要方法所需的概念。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号