...
首页> 外文期刊>Procedia Computer Science >Enterprise information security, a review of architectures and frameworks from interoperability perspective
【24h】

Enterprise information security, a review of architectures and frameworks from interoperability perspective

机译:企业信息安全,从互操作性的角度回顾体系结构和框架

获取原文
   

获取外文期刊封面封底 >>

       

摘要

With the growth of ICT opportunities, the enterprises have realized the significance of interoperability as a competitive advantage. Thus, many enterprises have adopted the main strategy of rapidly changing their structures to support interoperability. On the other hand, interoperability is incompatible with information security.The Enterprise Information Security Architecture (EISA) offers a framework upon which business security requirements, the risks and the threats are analyzed and a portfolio of the best integrated enterprise security solutions is put together. Frameworks and models introduced in the past six years have examined different aspects of EISA.We realized the diversity of the mentioned approaches and in this paper, first, we develop two facets according to which these approaches are categorized. These facets are abstraction level (holistic vs. partial) and architectural viewpoint (managerial vs. technical). As interoperability is the primary focus of our study and it is a broad concept, we restrict our discussion to holistic frameworks and models. In this regard, we survey the prominent holistic approaches namely Gartner, SABSA, RISE frameworks, AGM-based model and intelligent Service-Oriented EISA.In the next step, we compare the mentioned frameworks from technical, organizational and semantic interoperability aspects. We conclude that none of the frameworks, not even those which are holistic, practical and greatly elaborated, have explored interoperability clearly.We assert that the competitive advantages offered by interoperability, justify the costs needed for implementing the incompatible concepts of interoperability and security along with each other. In addition, we suggest that the requirements which are common to both interoperability and security should be extracted and the significance of interoperability to EISA should be apprehended.
机译:随着ICT机会的增长,企业已经意识到互操作性作为竞争优势的重要性。因此,许多企业采用了快速改变其结构以支持互操作性的主要策略。另一方面,互操作性与信息安全不兼容。企业信息安全体系结构(EISA)提供了一个框架,可在此框架上分析业务安全要求,风险和威胁,并提供最佳集成企业安全解决方案组合。过去六年中引入的框架和模型已经检查了EISA的不同方面。我们意识到了上述方法的多样性,在本文中,首先,我们从两个方面对这些方法进行了分类。这些方面是抽象级别(整体vs.部分)和体系结构观点(管理vs.技术)。由于互操作性是我们研究的重点,并且是一个广泛的概念,因此我们将讨论限制在整体框架和模型上。在这方面,我们调查了著名的整体方法,即Gartner,SABSA,RISE框架,基于AGM的模型和智能的面向服务的EISA。下一步,我们从技术,组织和语义互操作性方面比较了上述框架。我们得出的结论是,没有一个框架,甚至没有全面,实用和精心设计的框架都明确地探讨了互操作性。我们断言,互操作性提供的竞争优势证明了实施互操作性和安全性不兼容概念所需的成本以及彼此。此外,我们建议应提取互操作性和安全性共同的要求,并应理解互操作性对EISA的重要性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号