首页> 外文期刊>Concurrency, practice and experience >Cybersecurity compliance analysis as a service: Requirements specification and application scenarios
【24h】

Cybersecurity compliance analysis as a service: Requirements specification and application scenarios

机译:网络安全合规性分析即服务:需求规范和应用方案

获取原文
获取原文并翻译 | 示例

摘要

Cybersecurity compliance analysis is the process of assessing whether the behavior of an IT system or application conforms to the cybersecurity rules and regulations in force. This assessment can be offered as a service by exploiting available cloud technologies, and, indeed, it is one of the services classified by the Cloud Security Alliance (CSA) as part of the security information and event management (SIEM) category of the SecaaS (security as a service) domain. The definition and implementation of this typology of cloud services are challenging activities due to the complexity of both the reference business domain and the compliance analysis services to be provided themselves. The paper exploits a recently proposed requirements methodology, called GOReM(goal-oriented requirements methodology), to support the conceptualization and subsequent implementation of cybersecurity compliance analysis services. In particular, two different application scenarios regarding compliance analysis of an existing or under development IT system/ application are presented and discussed. In both the scenarios, GOReM allows to grasp and understand the many and complex issues to address for providing secure cloud services toworldwide customers, also due to the numerous, different and ever changing legal aspects, which have to be taken into account by service providers.
机译:网络安全合规性分析是评估IT系统或应用程序的行为是否符合现行网络安全规则和规定的过程。此评估可以通过利用可用的云技术提供为服务,并且确实是Cloud Security Alliance(CSA)归类为SecaaS(SecaS)安全信息和事件管理(SIEM)类别的一部分的服务之一(安全即服务)域。由于参考业务域和要自行提供的合规性分析服务的复杂性,因此云服务的这种类型的定义和实施具有挑战性。本文采用了最近提出的需求方法,称为GOReM(面向目标的需求方法),以支持网络安全合规性分析服务的概念化和后续实施。特别是,介绍和讨论了有关现有或正在开发的IT系统/应用程序的合规性分析的两个不同的应用程序场景。在这两种情况下,由于众多,不同且不断变化的法律方面,服务提供商必须考虑到这一点,GOReM可以理解和理解许多复杂的问题,以解决向全球客户提供安全的云服务的问题。

著录项

  • 来源
    《Concurrency, practice and experience》 |2018年第12期|e4289.1-e4289.20|共20页
  • 作者单位

    Department of Informatics, Modeling, Electronics and Systems Engineering, University of Calabria, P. Bucci 41C, 87036 Rende (CS), Italy;

    Department of Informatics, Modeling, Electronics and Systems Engineering, University of Calabria, P. Bucci 41C, 87036 Rende (CS), Italy;

    Department of Informatics, Modeling, Electronics and Systems Engineering, University of Calabria, P. Bucci 41C, 87036 Rende (CS), Italy;

    Department of Informatics, Modeling, Electronics and Systems Engineering, University of Calabria, P. Bucci 41C, 87036 Rende (CS), Italy;

    Department of Informatics, Modeling, Electronics and Systems Engineering, University of Calabria, P. Bucci 41C, 87036 Rende (CS), Italy;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    cloud computing; compliance analysis; cybersecurity; goal-oriented methodology; requirements engineering; SecaaS;

    机译:云计算;符合性分析;网络安全;面向目标的方法;需求工程;塞卡斯;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号