首页> 外文会议>IEEE Annual Ubiquitous Computing, Electronics Mobile Communication Conference >CSAT: A User-interactive Cyber Security Architecture Tool based on NIST-compliance Security Controls for Risk Management
【24h】

CSAT: A User-interactive Cyber Security Architecture Tool based on NIST-compliance Security Controls for Risk Management

机译:CSAT:基于风险管理的符合NIST的安全控制的用户交互网络安全架构工具

获取原文

摘要

Security risk management is a vital part of any system development, including e-commerce and other information systems that need security. Notably, NIST has developed cyber security and privacy controls, such as SP-800-53, to facilitate risk management for federal information systems. By integrating such NIST-compliance security controls, our CSAT is innovative to offer a user-interactive software tool for effectively facilitating the robust and secure architecture development of information systems in the way of enhancing overall risk management. It specifically promotes the enhancement of risk management by composing reports/graphs in different NIST defined do-mains/controls/capabilities specification effectively. This helps to reduce development cost, time, and manpower by using the tool to quickly define information system security standards based on NIST's security and privacy guidelines. The development of such a tool is of importance for risk management, e.g., security evaluation, risk assessment, controls implementation, system security planning). It can be used to optimize the risk management in the information system architecture in the lowest cost, while increasing the security robustness by systemically providing NIST guideline and risk management in the information system development level.
机译:安全风险管理是任何系统开发(包括电子商务和其他需要安全性的信息系统)中至关重要的部分。值得注意的是,NIST已开发了网络安全和隐私控制措施,例如SP-800-53,以促进联邦信息系统的风险管理。通过集成这种符合NIST的安全控制措施,我们的CSAT具有创新性,可以提供用户交互软件工具,以有效地促进信息系统的健壮和安全的体系结构开发,从而增强总体风险管理。它通过有效地在不同的NIST定义的域/控件/功能规范中组合报告/图形来特别促进增强风险管理。通过使用该工具根据NIST的安全和隐私准则快速定义信息系统安全标准,这有助于减少开发成本,时间和人力。开发这样的工具对于风险管理(例如安全性评估,风险评估,控制实施,系统安全性计划)非常重要。它可以用于以最低的成本优化信息系统体系结构中的风险管理,同时通过在信息系统开发级别系统地提供NIST准则和风险管理来提高安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号