首页> 外文期刊>ACM transactions on software engineering and methodology >Discovering Multidimensional Correlations among Regulatory Requirements to Understand Risk
【24h】

Discovering Multidimensional Correlations among Regulatory Requirements to Understand Risk

机译:发现监管要求之间的多维关联以了解风险

获取原文
获取原文并翻译 | 示例

摘要

Security breaches most often occur due to a cascading effect of failure among security constraints that collectively contribute to overall secure system behavior in a socio-technical environment. Therefore, during security certification activities, analysts must systematically take into account the nexus of causal chains that exist among security constraints imposed by regulatory requirements. Numerous regulatory requirements specified in natural language documents or listed in spreadsheets/databases do not facilitate such analysis. The work presented in this article outlines a stepwise methodology to discover and understand the multidimensional correlations among regulatory requirements for the purpose of understanding the potential for risk due to noncompliance during system operation. Our lattice algebraic computational model helps estimate the collective adequacy of diverse security constraints imposed by regulatory requirements and their interdependencies with each other in a bounded scenario of investigation. Abstractions and visual metaphors combine human intuition with metrics available from the methodology to improve the understanding of risk based on the level of compliance with regulatory requirements. In addition, a problem domain ontology that classifies and categorizes regulatory requirements from multiple dimensions of a socio-technical environment promotes a common understanding among stakeholders during certification and accreditation activities. A preliminary empirical investigation of our theoretical propositions has been conducted in the domain of The United States Department of Defense Information Technology Security Certification and Accreditation Process (DITSCAP). This work contributes a novel approach to understand the level of compliance with regulatory requirements in terms of the potential for risk during system operation.
机译:安全漏洞最常发生是由于安全约束之间的级联故障影响,共同导致社会技术环境中的总体安全系统行为。因此,在安全认证活动中,分析人员必须系统地考虑因法规要求所施加的安全约束中存在的因果链之间的联系。自然语言文档中指定或电子表格/数据库中列出的许多法规要求都不利于这种分析。本文介绍的工作概述了逐步的方法,以发现和理解监管要求之间的多维相关性,以了解系统运行过程中因不合规引起的潜在风险。我们的晶格代数计算模型可帮助估计在有限制的调查情况下,由监管要求施加的各种安全约束及其相互依存关系的总体充分性。抽象和视觉隐喻将人类的直觉与方法学中可用的度量标准相结合,以基于对法规要求的遵守程度来提高对风险的理解。此外,从社会技术环境的多个维度对监管要求进行分类和分类的问题域本体,可以促进利益相关者在认证和认可活动中的共识。我们在美国国防部信息技术安全认证和鉴定程序(DITSCAP)领域对我们的理论主张进行了初步的实证研究。这项工作提供了一种新颖的方法,可以根据系统运行期间的潜在风险来了解对法规要求的遵守程度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号