首页> 外文学位 >A conceptual design model for integrative information system security.
【24h】

A conceptual design model for integrative information system security.

机译:集成信息系统安全性的概念设计模型。

获取原文
获取原文并翻译 | 示例

摘要

One characteristic of contemporary industrial and commercial concerns is their deepening dependence on computers and information technology apparatus. Rather than being restricted to ancillary (clerical and accounting-related) activities, they are increasingly relied on to support mainline operational functions. This is most evident among those firms now undertaking transitions from traditionally disaggregated (function-unit specific) MIS-type structures to fully-integrated information system architectures (i.e., Enterprise-Wide Management Support Systems. This suggests the need for a corresponding transition from disaggregated to integrated information system security structures. It is the procedural and mechanical provisions that underlie this complementary transition that are the primary focus of this dissertation.; As things now stand, what appears to be the best guide, albeit a bit indirectly, as to what an integrated information system security structure might look like is the Cooperative Engagement Capability (CEC) under development in the U.S. Military sector. Key to the CEC approach is the shift from unit-specific (disaggregated) to more clustered (integrative) control over the deployment of defensive assets. A central higher order authority controls the decisions regarding the allocation of countermeasures available to units in a geographical area, in order to increase allocative rationality. The defensive assets of an enterprise are limited and the centralized rational allocation of them would require integrative information system security in order to assure the survival and success of the firm now dependent upon information. The military-type approach to security relies upon intelligence processing (vs. data processing) provisions. This dissertation develops a top-down conceptual design model, which integrates information security into information systems and information operations by applying military concepts from military operations and military intelligence. The conceptual integrative information system security (I2S2) model will contain three levels of decomposed design. Each level of decomposition will show more granular integrative information system security design. Information systems security designers will find the level three I2S2 model useful to incorporate information system security as an integral component of the information system design.{09}A review of current literature reveals that there is no existing overarching architecture for integrative information system security to support information operations. Nearly every day, reports of information security incidents appear in the media and practitioners' literature, clearly showing that there is a pressing need for such an integrative information system security architectural framework. The catastrophic events of September 11, 2001 clearly demonstrate the immediate need for an integrative information system security subsystem. Human involvement as the decision-makers and non-integrative information system security on September 11, 2001 delayed countermeasures, which had they been taken minutes earlier could have drastically altered history.; Prior research in event-response models as published in the literature provides a starting point for the new conceptual integrative information system security model. This dissertation built upon these earlier research efforts and introduced new concepts forming a unique model that formalizes structure for information system security. This model consists of six components, derived through a structured approach. A chapter for each component will discuss that component's design development. A model base approach allows the formulation of threat scenarios upon which different integrative facilities can process acquired information to dynamically select and implement countermeasures.
机译:当代工业和商业关注的特征之一是它们对计算机和信息技术设备的加深依赖。他们不再局限于辅助(与文书和会计相关的)活动,而是越来越多地依赖它们来支持主线操作功能。在那些正在从传统的分解(特定于功能单元)的MIS类型结构过渡到完全集成的信息系统体系结构(即企业级管理支持系统)的公司中,这最为明显。这表明需要从分解的结构进行相应的过渡。到集成信息系统安全结构。这是互补的过渡基础上的程序和机械规定,是本论文的主要重点。就目前情况而言,似乎是最好的指南,尽管有点间接地是什么。一个集成的信息系统安全结构可能看起来像是美国军事部门正在开发的合作参与能力(CEC),CEC方法的关键是从对单位的特定(分散)到更集中(集成)的部署控制转变防御性资产的中央高级管理机构控制有关分配的决策为了增加分配的合理性,对地理区域内的单位可用的对策。企业的防御性资产是有限的,对其的集中合理分配将需要集成的信息系统安全性,以确保现在依赖信息的企业的生存和成功。军事类型的安全方法依赖于情报处理(相对于数据处理)规定。本文建立了一种自上而下的概念设计模型,通过运用军事行动和军事情报中的军事概念将信息安全集成到信息系统和信息行动中。概念性集成信息系统安全性(I2S2)模型将包含三个层次的分解设计。分解的每个级别将显示更详细的集成信息系统安全性设计。信息系统安全设计人员会发现三级I2S2模型对于将信息系统安全性纳入信息系统设计的组成部分非常有用。{09}对现有文献的回顾表明,目前尚没有支持集成信息系统安全性的总体架构。信息操作。几乎每天都有关于信息安全事件的报告出现在媒体和从业人员的文献中,清楚地表明,迫切需要这种集成的信息系统安全体系结构框架。 2001年9月11日的灾难性事件清楚表明,迫切需要集成信息系统安全子系统。作为决策者的人为参与和2001年9月11日的非集成信息系统安全,推迟了对策,如果在几分钟前采取对策,可能会大大改变历史。文献中发表的对事件响应模型的先前研究为新的概念集成信息系统安全模型提供了一个起点。本文基于这些早期的研究成果,并引入了新的概念,形成了一个独特的模型,该模型使信息系统安全的结构形式化。该模型由六个组成部分,通过结构化方法得出。每个组件的一章将讨论该组件的设计开发。基于模型的方法允许制定威胁情景,不同的集成设施可在此基础上处理获取的信息,以动态选择和实施对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号