首页> 外文会议>International Conference for Internet Technology and Secured Transactions >An applied methodology for information security and assurance: A study case for cloud computing
【24h】

An applied methodology for information security and assurance: A study case for cloud computing

机译:信息安全和保证的应用方法论:云计算的研究案例

获取原文

摘要

Information security is one of the main concerns in many fields of computer and information technologies, and even more on new emerging technologies such as cloud computing. Current security standards and models usually focus on "what" has to be done about security, but they do not propose "how" to deal with the inherent complexity of assuring modern infrastructures. Security standards usually produce large check lists describing security countermeasures, but they lack a comprehensive and complete process to define the security requirements of information being managed. As a consequence, security implementations may miss important security controls, and they cannot guarantee a consistent and in-depth security implementation at the different layers of the system. We propose a methodology with a novel hierarchical approach to guide a comprehensive and complete assurance process. Real use cases are shown, by applying our methodology to assure a private cloud being developed at the Universidad de Costa Rica (UCR).
机译:信息安全是计算机和信息技术许多领域的主要关注之一,甚至在诸如云计算之类的新兴技术上也是如此。当前的安全标准和模型通常集中在关于安全性必须“做什么”上,但是它们没有提出“如何”来处理确保现代基础设施固有的复杂性。安全标准通常会产生描述安全对策的大型检查表,但是它们缺乏全面而完整的流程来定义所管理信息的安全要求。结果,安全实施可能会错过重要的安全控制,并且它们不能保证在系统的不同层上进行一致且深入的安全实施。我们提出了一种具有新颖的分层方法的方法,以指导全面而完整的保证程序。通过应用我们的方法来确保哥斯达黎加大学(UCR)正在开发私有云,来显示实际用例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号