首页> 外文会议>International Conference on Network and System Security >Business Process-Based Information Security Risk Assessment
【24h】

Business Process-Based Information Security Risk Assessment

机译:基于业务流程的信息安全风险评估

获取原文

摘要

Limited information security budget in organizations make it necessary to effectively prioritize among security requirements. The goal is to make the most out of the available budget and to achieve a balanced overall security level. This leads to maximize the investment outcome. Many existing information security risk assessment approaches identify and assess risks to critical assets and are asset-driven approaches. These are limited in that it is hard to keep track of dependencies between assets and to produce realistic estimates of their values to an organization. We present a new security risk assessment approach focusing on business goals rather than assets and the processes supporting or contributing to these goals. Risks are identified and evaluated on a business process level and aggregated over all such processes depending on their criticality, role and importance for the organization as a whole. We illustrate our approach using examples from the banking industry, as well as discuss how our approach deals with some of the ambiguities involved in expert intensive and asset-driven information security risk assessment.
机译:有限的信息安全预算在组织中使有必要有效地在安全要求之间优先考虑。目标是充分利用可用预算,并实现平衡的整体安全级别。这导致最大化投资结果。许多现有信息安全风险评估方法识别并评估关键资产的风险,并是资产驱动的方法。这些是有限的,因为很难跟踪资产之间的依赖性,并将其价值的现实估算结果产生给组织。我们提出了一种专注于业务目标而不是资产和支持或贡献这些目标的流程的新安全风险评估方法。在业务流程级别确定和评估风险,并根据其整体组织的关键性,角色和重要性来汇总所有此类流程。我们说明了我们使用银行业的例子的方法,以及讨论我们的方法如何处理专业和资产驱动信息安全风险评估所涉及的一些含糊之处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号