首页> 外文OA文献 >Navigating between information security management documents : a modeling methodology
【2h】

Navigating between information security management documents : a modeling methodology

机译:在信息安全管理文档之间导航:建模方法

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Organizations no longer draft their own standards. Instead, organizations take advantage of the available international standards. One standard may not cover all the organization's needs, requiring organizations to implement more than one standard. The same aspect in an organization may be covered by two or more standards, creating an overlap. An awareness of such overlaps led to various institutions creating mapping documents illustrating how a control from one standard relates to a control from a different standard. The mapping documents are consulted by the end user, to identify how a control in one standard may relate to other standards. This allows the end user to navigate between the standards documents. These mapping documents are valuable to a person who wishes to grasp how different standards deal with a specific control. However, the navigation between standards is a cumbersome task. In order to navigate between the standards the end user is required to consult three or more documents, depending on the number of standards that are mapped to the control being investigated. The need for a tool that will provide fast and efficient navigation between standards was identified. The data tier of the tool is the focus of this dissertation. As a result, this research proposes a modeling methodology that will allow for the modeling of the standards and the information about the mapping between standards, thereby contributing to the creation of tools to aid in the navigation between standards. A comparison between the major data modeling paradigms identifies multi-dimensional modeling as the most appropriate technique to model standards. Adapting an existing modeling methodology to cater for the modeling standards, yield a five step standard modeling methodology. Once modeled, the standards can be physically implemented as a database. The database schema that results from the standard modeling methodology adheres to a specific pattern and can thus be expressed according to well-defined meta-model. This allows for the generation of SQL statements by a tool with limited knowledge of the standards in a way that allows the quick navigation between standards. To determine the usefulness of the standards modeling methodology the research presents iv a prototype that utilizes the well-defined meta-model to navigate between standards. It is shown that, as far as navigation is concerned, no code changes are necessary when adding a new standard or new mappings between standards. This research contributes to the creation of a tool that can easily navigate between standards by providing the ability to model the data tier in such a way that it is extensible, yet remains independent of the application and presentation tiers.
机译:组织不再起草自己的标准。相反,组织可以利用可用的国际标准。一种标准可能无法满足组织的所有需求,因此要求组织实施多个标准。组织中的同一方面可能被两个或多个标准覆盖,从而产生了重叠。对这种重叠的认识导致各种机构创建了映射文档,这些文档说明了一个标准的控件与另一个标准的控件之间的关系。最终用户将查阅映射文件,以识别一个标准中的控件如何与其他标准相关。这允许最终用户在标准文档之间导航。这些映射文档对于希望掌握不同标准如何处理特定控件的人来说非常有价值。然而,标准之间的导航是一项繁琐的任务。为了在标准之间导航,最终用户需要查阅三个或更多文档,具体取决于映射到要研究的控件的标准数量。已经确定需要一种工具,以在标准之间提供快速有效的导航。该工具的数据层是本文的重点。结果,这项研究提出了一种建模方法,该方法将允许对标准和有关标准之间的映射的信息进行建模,从而有助于创建工具以帮助在标准之间导航。主要数据建模范例之间的比较将多维建模确定为建模标准的最合适技术。调整现有的建模方法以适应建模标准,可产生五步标准的建模方法。一旦建模,这些标准就可以物理上实现为数据库。由标准建模方法得出的数据库模式遵循特定的模式,因此可以根据定义明确的元模型来表示。这允许使用对标准知识了解有限的工具以允许在标准之间快速导航的方式生成SQL语句。为了确定标准建模方法的有效性,本研究提出了一个原型,该原型利用定义明确的元模型在标准之间导航。结果表明,就导航而言,在添加新标准或标准之间的新映射时,无需更改代码。这项研究有助于创建一种工具,该工具可以通过以可扩展的方式对数据层进行建模的能力,而又独立于应用程序和表示层,从而轻松地在标准之间进行导航。

著录项

  • 作者

    Domingues Steve;

  • 作者单位
  • 年度 2010
  • 总页数
  • 原文格式 PDF
  • 正文语种 English
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号