首页> 外文OA文献 >Obligations to enforce prohibitions: On the adequacy of security policies
【2h】

Obligations to enforce prohibitions: On the adequacy of security policies

机译:强制执行禁止的义务:关于安全策略的充分性

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。
获取外文期刊封面目录资料

摘要

Security policies in organisations typically take the form of obligations for the employees. However, it is often unclear what the purpose of such obligations is, and how these can be integrated in the operational processes of the organisation. This can result in policies that may be either too strong or too weak, leading to unnecessary productivity loss, or the possibility of becoming victim to attacks that exploit the weaknesses, respectively. In this paper, we propose a framework in which the security obligations of employees are linked directly to prohibitions that prevent external agents (attackers) from reaching their goals. We use graph-based and logicbased approaches to formalise and reason about such policies, and show how the framework can be used to verify correctness of the associated refinements. The framework can assist organisations in aligning security policies with their threat model.
机译:组织中的安全策略通常采取员工义务的形式。但是,通常不清楚此类义务的目的是什么,以及如何将其整合到组织的运营流程中。这可能会导致策略太强或太弱,导致不必要的生产力损失,或者有可能分别成为利用这些弱点的攻击的受害者。在本文中,我们提出了一个框架,在该框架中,员工的安全义务直接与阻止外部代理(攻击者)实现其目标的禁止相关。我们使用基于图和基于逻辑的方法来对此类策略进行形式化和推理,并说明如何使用该框架来验证相关改进的正确性。该框架可以帮助组织使安全策略与其威胁模型保持一致。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号