首页> 外文会议>International Conference on Secure Cyber Computing and Communications >Automation of Security and Privacy Controls for Efficient Information Security Management
【24h】

Automation of Security and Privacy Controls for Efficient Information Security Management

机译:安全和隐私控制的自动化,以了解高效信息安全管理

获取原文

摘要

Information security management incorporates both security and privacy controls where security program deals with the security of information and information systems to assure confidentiality, integrity, and availability and privacy programs handle agreement with appropriate confidentiality requirements and problems integrated with personally identifiable information. So, when it comes to the functioning and controlling of any aspect of an organization both controls should be properly implemented. However, the complexity and the scope of organizations with rapidly evolving technology risks make management difficult. To achieve efficiency in implementation and monitoring, controls are required to be managed automatically. It is shown in the paper that 47.8% from NIST Special Publication 800-53 revision 5 [3] recommended controls for high impact systems can be automated. To facilitate automation for rest 52.2% non-automatable controls, it is shown that implementation of compensating controls provides the same degree of security. Moreover, the paper includes examples of tools and applications that support automation of controls and examples of challenges in the automation process.
机译:信息安全管理包括安全性和隐私控制,安全计划处理信息和信息系统的安全性,以确保机密性,完整性和可用性和隐私计划处理协议,并与个人可识别信息集成的适当机密性要求和问题。因此,当涉及到任何方面的功能和控制,两个控件都应该正确实现。然而,具有迅速发展的技术风险的组织的复杂性和范围使管理难以实现管理层。为了实现实施和监控的效率,需要自动管理控件。它显示在本文中,47.8%来自NIST特刊800-53修订版5 [3]高冲击系统的推荐控制可以自动化。为促进休息的自动化52.2%的非自动控制,结果表明补偿控制的实施提供了相同程度的安全性。此外,本文包括支持自动化过程中的控制和挑战的自动化的工具和应用的示例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号