首页> 外文期刊>Journal of computer networks and communications >System Health Monitoring Using a Novel Method: Security Unified Process
【24h】

System Health Monitoring Using a Novel Method: Security Unified Process

机译:使用新方法进行系统健康监控:安全统一过程

获取原文
获取原文并翻译 | 示例
           

摘要

Iterative and incremental mechanisms are not usually considered in existing approaches for information security management System (ISMS). In this paper, we propose SUP (security unified process) as a unified process to implement a successful and high-quality ISMS. A disciplined approach can be provided by SUP to assign tasks and responsibilities within an organization. The SUP architecture comprises static and dynamic dimensions; the static dimension, or disciplines, includes business modeling, assets, security policy, implementation, configuration and change management, and project management. The dynamic dimension, or phases, contains inception, analysis and design, construction, and monitoring. Risk assessment is a major part of the ISMS process. In SUP, we present a risk assessment model, which uses a fuzzy expert system to assess risks in organization. Since, the classification of assets is an important aspect of risk management and ensures that effective protection occurs, a Security Cube is proposed to identify organization assets as an asset classification model. The proposed model leads us to have an offline system health monitoring tool that is really a critical need in any organization.
机译:信息安全管理系统(ISMS)的现有方法通常不考虑迭代和增量机制。在本文中,我们提出将SUP(安全统一过程)作为实现成功和高质量ISMS的统一过程。 SUP可以提供一种纪律严明的方法来在组织内分配任务和职责。 SUP体系结构包括静态和动态维度。静态范围或学科包括业务建模,资产,安全策略,实施,配置和变更管理以及项目管理。动态维度或阶段包含启动,分析和设计,构造和监视。风险评估是ISMS流程的重要组成部分。在SUP中,我们提出了一种风险评估模型,该模型使用模糊专家系统来评估组织中的风险。由于资产分类是风险管理的重要方面,并确保有效的保护发生,因此提出了一个安全多维数据集以将组织资产标识为资产分类模型。提出的模型使我们拥有一个脱机的系统运行状况监视工具,这对于任何组织而言都是至关重要的。

著录项

  • 来源
    《Journal of computer networks and communications》 |2012年第1期|151205.1-151205.20|共20页
  • 作者单位

    Department de Genie Informatique et Ginie Logiciel, Ecok Polytechnique de Montreal, P.O. Box 6079, Succ. Downtown, Montreal, QC, Canada H3C 3A7;

    Department de Genie Informatique et Ginie Logiciel, Ecok Polytechnique de Montreal, P.O. Box 6079, Succ. Downtown, Montreal, QC, Canada H3C 3A7;

    Department de Genie Informatique et Ginie Logiciel, Ecok Polytechnique de Montreal, P.O. Box 6079, Succ. Downtown, Montreal, QC, Canada H3C 3A7;

    Department of Computer Engineering & Information Technology, Amirkabir University of Technology, 424 Hafez Avenue, Tehran, Iran;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号