...
首页> 外文期刊>Information management & computer security >The use of business process modelling in information systems security analysis and design
【24h】

The use of business process modelling in information systems security analysis and design

机译:业务流程建模在信息系统安全分析和设计中的使用

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The increasing reliance of organisations on information systems connected to or extending over open data networks has established information security as a critical success factor for modern organisations. Risk analysis appears to be the predominant methodology for the introduction of security in information systems (IS). However, risk analysis is based on a very simple model of IS as consisting of assets, mainly data, hardware and software, which are vulnerable to various threats. Thus, risk analysis cannot provide for an understanding of the organisational environment in which IS operate. We believe that a comprehensive methodology for information systems security analysis and design (IS-SAD) should incorporate both risk analysis and organisational analysis, based on business process modelling (BPM) techniques. This paper examines the possible contribution of BPM techniques to IS-SAD and identifies the conceptual and methodological requirements for a technique to be used in this context. Based on these requirements, several BPM techniques have been reviewed. The review reveals the need for either adapting and combining current techniques or developing new, specialised ones.
机译:组织对连接到开放数据网络或通过开放数据网络扩展的信息系统的依赖性越来越强,这已将信息安全性确立为现代组织成功的关键因素。风险分析似乎是在信息系统(IS)中引入安全性的主要方法。但是,风险分析基于一个非常简单的IS模型,该模型由易受各种威胁攻击的资产(主要是数据,硬件和软件)组成。因此,风险分析无法理解IS在其中运行的组织环境。我们认为,基于业务流程建模(BPM)技术的信息系统安全分析和设计(IS-SAD)的综合方法应该同时包含风险分析和组织分析。本文研究了BPM技术对IS-SAD的可能贡献,并确定了在此背景下使用的技术的概念和方法要求。基于这些要求,已经审查了几种BPM技术。审查显示需要适应和结合当前技术或开发新的专门技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号