...
首页> 外文期刊>Information management & computer security >Ontology-based information security compliance determination and control selection on the example of ISO 27002
【24h】

Ontology-based information security compliance determination and control selection on the example of ISO 27002

机译:基于本体的信息安全合规性确定和控制选择,以ISO 27002为例

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Purpose - The purpose of this paper is to provide a method to formalize information security control descriptions and a decision support system increasing the automation level and, therefore, the cost efficiency of the information security compliance checking process. The authors advanced the state-of-the-art by developing and applying the method to ISO 27002 information security controls and by developing a semantic decision support system. Design/methodology/approach - The research has been conducted under design science principles. The formalized information security controls were used in a compliance/risk management decision support system which has been evaluated with experts and end-users in real-world environments. Findings - There are different ways of obtaining compliance to information security standards. For example, by implementing countermeasures of different quality depending on the protection needs of the organization. The authors developed decision support mechanisms which use the formal control descriptions as input to support the decision-maker at identifying the most appropriate countermeasure strategy based on cost and risk reduction potential. Originality/value - Formalizing and mapping the ISO 27002 controls to the security ontology enabled the authors to automatically determine the compliance status and organization-wide risk-level based on the formal control descriptions and the modelled environment, including organizational structures, IT infrastructure, available countermeasures, etc. Furthermore, it allowed them to automatically determine which countermeasures are missing to ensure compliance and to decrease the risk to an acceptable level.
机译:目的-本文的目的是提供一种形式化信息安全控制描述的方法,以及一种决策支持系统,以提高自动化水平,从而提高信息安全合规性检查过程的成本效率。作者通过将方法开发和应用到ISO 27002信息安全控制中以及通过开发语义决策支持系统来提高了技术水平。设计/方法/方法-研究是根据设计科学原理进行的。正式的信息安全控制已用于合规性/风险管理决策支持系统中,该系统已与专家和最终用户在现实环境中进行了评估。调查结果-有多种方法可以使信息安全标准得到遵守。例如,通过根据组织的保护需求实施不同质量的对策。作者开发了决策支持机制,该机制使用形式化的控制描述作为输入,以支持决策者根据成本和降低风险的潜力确定最合适的对策策略。原创性/价值-将ISO 27002控件形式化并映射到安全性本体,使作者能够基于正式的控件描述和建模环境(包括组织结构,IT基础架构)自动确定合规状态和组织范围内的风险级别此外,它还允许他们自动确定缺少哪些对策,以确保合规性并将风险降低到可接受的水平。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号