...
首页> 外文期刊>European Journal of Operational Research >Optimal selection of IT security safeguards from an existing knowledge base
【24h】

Optimal selection of IT security safeguards from an existing knowledge base

机译:从现有知识库中选择最佳的IT安全保障措施

获取原文
获取原文并翻译 | 示例
           

摘要

In this paper, a combinatorial optimization model is proposed to efficiently select security safeguards in order to protect IT infrastructures and systems. The approach is designed to provide very concrete decision support for an organization as a whole or separately for specific systems. It can be applied in practice without requiring the decision maker himself to collect extensive input data. This is accomplished by using an existing comprehensive and highly accepted knowledge base as a basis for decision making. For our analysis, we use the publicly available IT baseline protection catalogues of the German Federal Office for Information Security (BSI). The catalogues contain more than 500 threats and over 1200 safeguard alternatives to choose from. Applying our model, it is possible to make use of this knowledge and determine optimal selections of safeguards according to given security requirements. The approach supports the decision maker in establishing an effective baseline security strategy. (C) 2015 Elsevier B.V. and Association of European Operational Research Societies (EURO) within the International Federation of Operational Research Societies (IFORS). All rights reserved.
机译:在本文中,提出了一种组合优化模型来有效地选择安全措施,以保护IT基础架构和系统。该方法旨在为整个组织或针对特定系统的组织提供非常具体的决策支持。它可以在实践中应用,而无需决策者自己收集大量的输入数据。这是通过使用现有的,广泛接受的知识库作为决策基础来实现的。对于我们的分析,我们使用德国联邦信息安全局(BSI)的公共IT基准保护目录。这些目录包含500多种威胁和1200多种防护措施可供选择。应用我们的模型,就有可能利用这些知识并根据给定的安全要求确定最佳的保障措施选择。该方法支持决策者建立有效的基线安全策略。 (C)2015年Elsevier B.V.和国际运营研究学会联合会(IFORS)中的欧洲运营研究学会协会(EURO)。版权所有。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号