首页> 外文期刊>Information management & computer security >Resolving vulnerability identification errors using security requirements on business process models
【24h】

Resolving vulnerability identification errors using security requirements on business process models

机译:使用业务流程模型上的安全要求来解决漏洞识别错误

获取原文
获取原文并翻译 | 示例

摘要

Purpose - In any information security risk assessment, vulnerabilities are usually identified by information-gathering techniques. However, vulnerability identification errors - wrongly identified or unidentified vulnerabilities - can occur as uncertain data are used. Furthermore, businesses' security needs are not considered sufficiently. Hence, security functions may not protect business assets sufficiently and cost-effectively. This paper aims to resolve vulnerability errors by analysing the security requirements of information assets in business process models. Design/methodology/approach - Business process models have been selected for use, because there is a close relationship between business process objectives and risks. Security functions are evaluated in terms of the information flow of business processes regarding their security requirements. The claim that vulnerability errors can be resolved was validated by comparing the results of a current risk assessment approach with the proposed approach. The comparison is conducted both at three entities of an insurance company, as well as through a controlled experiment within a survey among security professionals. Findings - Vulnerability identification errors can be resolved by explicitly evaluating security requirements in the course of business; this is not considered in current assessment methods. Originality/value - It is shown that vulnerability identification errors occur in practice. With the explicit evaluation of security requirements, identification errors can be resolved. Risk assessment methods should consider the explicit evaluation of security requirements.
机译:目的-在任何信息安全风险评估中,通常通过信息收集技术来识别漏洞。但是,由于使用了不确定的数据,可能会发生漏洞识别错误-错误地识别或未识别的漏洞。此外,企业的安全需求未得到充分考虑。因此,安全功能可能无法充分有效地保护企业资产。本文旨在通过分析业务流程模型中信息资产的安全要求来解决漏洞错误。设计/方法/方法-已选择使用业务流程模型,因为业务流程目标和风险之间存在密切的关系。根据业务流程有关其安全要求的信息流来评估安全功能。通过将当前风险评估方法的结果与提议的方法进行比较,验证了可以解决漏洞错误的说法。比较是在保险公司的三个实体中进行的,也可以通过对安全专业人员进行的调查中的对照实验来进行。结果-可以通过在业务过程中明确评估安全要求来解决漏洞识别错误;当前的评估方法中未考虑这一点。原创性/价值-表明在实践中会发生漏洞识别错误。通过对安全要求的明确评估,可以解决识别错误。风险评估方法应考虑对安全要求的明确评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号