首页> 外文会议>IEEE Annual Ubiquitous Computing, Electronics Mobile Communication Conference >CSAT: A User-interactive Cyber Security Architecture Tool based on NIST-compliance Security Controls for Risk Management
【24h】

CSAT: A User-interactive Cyber Security Architecture Tool based on NIST-compliance Security Controls for Risk Management

机译:CSAT:基于NIST-Compliance安全控制的用户交互式网络安全架构工具,用于风险管理

获取原文

摘要

Security risk management is a vital part of any system development, including e-commerce and other information systems that need security. Notably, NIST has developed cyber security and privacy controls, such as SP-800-53, to facilitate risk management for federal information systems. By integrating such NIST-compliance security controls, our CSAT is innovative to offer a user-interactive software tool for effectively facilitating the robust and secure architecture development of information systems in the way of enhancing overall risk management. It specifically promotes the enhancement of risk management by composing reports/graphs in different NIST defined do-mains/controls/capabilities specification effectively. This helps to reduce development cost, time, and manpower by using the tool to quickly define information system security standards based on NIST's security and privacy guidelines. The development of such a tool is of importance for risk management, e.g., security evaluation, risk assessment, controls implementation, system security planning). It can be used to optimize the risk management in the information system architecture in the lowest cost, while increasing the security robustness by systemically providing NIST guideline and risk management in the information system development level.
机译:安全风险管理是任何系统发展的重要组成部分,包括电子商务等信息化系统需要进行安全。值得注意的是,NIST已经开发网络安全和隐私控制,如SP-800-53,以促进联邦信息系统风险管理。通过整合这种NIST遵守安全控制,我们的CSAT是创新提供了有效地促进加强全面风险管理的方式信息系统的稳健和安全的体系结构开发的用户交互的软件工具。它专门促进风险管理通过组合报告增强/在不同的NIST定义的图表做,电源/控制/功能有效规范。这有助于通过使用该工具来快速定义基于NIST的安全和隐私准则信息系统安全标准,以降低开发成本,时间和人力。这种工具的开发是风险管理,例如,安全评估,风险评估,控制实施,系统安全规划)的重要性。它可用于优化的信息系统架构,以最低的成本风险管理,同时通过系统地提供NIST指引和风险管理信息系统的发展水平提高了安全稳健性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号