首页> 外文会议>Portland International Conference on Management of Engineering and Technology >Bridging the gap between business and technology in strategic decision-making for cyber security management
【24h】

Bridging the gap between business and technology in strategic decision-making for cyber security management

机译:弥合网络战略管理中业务与技术之间的鸿沟

获取原文

摘要

System architectures are getting more and more complex. Thus, making strategic decisions when it comes to managing systems is difficult and needs proper support. One arising issue that managers need to take into account when changing their technology is security. No business is spared from threats in today's connected society. The repercussions of not paying this enough attention could result in loss of money and in case of cyber physical systems, also human lives. Thus, system security has become a high-level management issue. There are various methods of assessing system security. A common method that allows partial automation is attack graph based security analysis. This particular method has many variations and wide tool support. However, a complex technical analysis like the attack graph based one needs experts to run it and interpret the results. In this paper we study what kind of strategic decisions that need the support of threat analysis and how to improve an attack graph based architecture threat assessment method to fit this task. The needs are gathered from experts working with security management and the approach is inspired by an enterprise architecture language called ArchiMate. The paper contains a working example. The proposed approach aims to bridge the gap between technical analysis and business analysis making system architectures easier to manage.
机译:系统架构变得越来越复杂。因此,在管理系统时做出战略决策很困难,需要适当的支持。安全性是管理人员在更改其技术时需要考虑的一个新出现的问题。在当今互联互通的社会中,没有任何企业能幸免于难。没有给予足够重视的后果可能导致金钱损失,并且在网络物理系统和人类生命的情况下。因此,系统安全性已成为高级管理问题。有多种评估系统安全性的方法。允许部分自动化的一种常用方法是基于攻击图的安全性分析。这种特殊的方法有许多变体和广泛的工具支持。但是,复杂的技术分析(例如基于攻击图的分析)需要专家来运行它并解释结果。在本文中,我们研究需要什么样的战略决策来支持威胁分析,以及如何改进基于攻击图的体系结构威胁评估方法以适合此任务。需求是从与安全管理一起工作的专家那里收集的,而该方法是受一种称为ArchiMate的企业体系结构语言的启发。本文包含一个工作示例。提出的方法旨在弥合技术分析和业务分析之间的鸿沟,使系统架构更易于管理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号