首页> 外文期刊>Software and systems modeling >An integrated conceptual model for information system security risk management supported by enterprise architecture management
【24h】

An integrated conceptual model for information system security risk management supported by enterprise architecture management

机译:企业架构管理支持信息系统安全风险管理的集成概念模型

获取原文
获取原文并翻译 | 示例
       

摘要

Risk management is today a major steering tool for any organisation wanting to deal with information system (IS) security. However, IS security risk management (ISSRM) remains a difficult process to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with enterprise architecture management (EAM) contributes to deal with these issues. A first step towards a better integration of both domains is to define an integrated EAM-ISSRM conceptual model. This paper is about the elaboration and validation of this model. To do so, we improve an existing ISSRM domain model, i.e. a conceptual model depicting the domain of ISSRM, with the concepts of EAM. The validation of the EAM-ISSRM integrated model is then performed with the help of a validation group assessing the utility and usability of the model.
机译:风险管理今天是任何想要处理信息系统(IS)安全性的组织的主要转向工具。但是,安全风险管理(ISSRM)仍然是建立和维护的难度过程,主要是在复杂和连接的多条规定的情况下。我们声称与企业架构管理(OAM)的连接有助于处理这些问题。迈向更好地集成两个域的第一步是定义集成的EAM-ISSRM概念模型。本文是关于该模型的制定和验证。为此,我们改进了现有的ISSRM域模型,即描述了描述了IAM的概念的概念模型。然后,在验证组的帮助下进行评估模型的实用性和可用性,执行EAM-ISSRM集成模型的验证。

著录项

  • 来源
    《Software and systems modeling》 |2019年第3期|2285-2312|共28页
  • 作者单位

    Luxembourg Inst Sci & Technol 5 Ave Hauts Fourneaux L-4362 Esch Sur Alzette Luxembourg;

    Luxembourg Inst Sci & Technol 5 Ave Hauts Fourneaux L-4362 Esch Sur Alzette Luxembourg;

    Luxembourg Inst Sci & Technol 5 Ave Hauts Fourneaux L-4362 Esch Sur Alzette Luxembourg;

    Luxembourg Inst Sci & Technol 5 Ave Hauts Fourneaux L-4362 Esch Sur Alzette Luxembourg;

    Luxembourg Inst Sci & Technol 5 Ave Hauts Fourneaux L-4362 Esch Sur Alzette Luxembourg;

    Univ Twente Chair Informat Syst Enschede Netherlands;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Risk management; Security; Enterprise architecture; ArchiMate;

    机译:风险管理;安全;企业架构;重建;
  • 入库时间 2022-08-18 21:30:44

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号