首页> 外文会议>Portland International Conference on Management of Engineering and Technology >Capability Effectiveness Testing for Architectural Resiliency in Financial Systems
【24h】

Capability Effectiveness Testing for Architectural Resiliency in Financial Systems

机译:金融系统中建筑弹性的能力有效性测试

获取原文

摘要

Increasing interconnectivity in financial institutions and markets along with complex, interdependent architectures present unique enterprise risks. While technological advances continuously improve the reliability and trustworthiness of individual technological system components, the complex, collaborative architectures relied on by most financial organizations present substantial challenges that span technology, personnel, and process dimensions. As systems and threat environments grow in sophistication, approaches to security testing and evaluation must evolve as well. Traditional approaches to cyber security testing may still be useful to evaluate basic architectural components, however new techniques are needed to enable the enterprise to construct simulation exercises that model real-world threat conditions and test the resiliency of all architectural components, including personnel and process dimensions. Organizations must not only establish capabilities to recognize breach attempts, but take decisive response action under conditions of uncertainty and stress. Techniques to evaluate resilient enterprise architectures sometimes underemphasize the threats surrounding human dimensions. This paper examines emerging risk considerations presented by increased connectivity among financial services enterprises. It explores new requirements for testing and evaluation of enterprise resiliency as well as organizational detection and response capabilities. The paper considers industry and other external environmental factors driving the need to develop comprehensive evaluation approaches to evaluate the effectiveness of enterprise capabilities in order to embed capability effectiveness assessments within enterprise risk management practices. Limitations of current cyber testing approaches in simulating the emerging cyber threat environment are identified, and the value of realistic, time-bound drills and tests that mimic the stress of real-world cyber events are explored.
机译:增加金融机构和市场的互连以及复杂,相互依存的架构目前具有独特的企业风险。虽然技术进步不断提高各个技术系统组件的可靠性和可信度,但大多数金融组织依赖的复杂,协作架构依赖于跨越技术,人员和过程尺寸的大量挑战。随着系统和威胁环境的增长,安全测试和评估的方法也必须进化。传统的网络安全测试方法仍然有助于评估基本架构组件,但是需要新技术来使企业能够构建模拟仿真练习,以模型实现现实世界威胁条件,并测试所有建筑组件的弹性,包括人员和过程尺寸。组织不仅必须建立能力以识别违规行为,而且在不确定性和压力条件下采取决定性的反应行动。评估弹性企业架构的技术有时强调了围绕人类尺寸的威胁。本文审查了金融服务企业之间增加了连通性的新出现风险考虑因素。它探讨了企业弹性测试和评估的新要求以及组织检测和响应能力。本文考虑了行业和其他外部环境因素,促进了开发综合评估方法,以评估企业能力的有效性,以便在企业风险管理实践中嵌入能力效力评估。确定了模拟新兴网络威胁环境的当前网络测试方法的限制,探讨了模仿现实世界网络事件的压力的现实,时频钻探和测试的价值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号