首页> 外文期刊>Software and systems modeling >An integrated conceptual model for information system security risk management supported by enterprise architecture management
【24h】

An integrated conceptual model for information system security risk management supported by enterprise architecture management

机译:企业架构管理支持的信息系统安全风险管理的集成概念模型

获取原文
获取原文并翻译 | 示例
           

摘要

Risk management is today a major steering tool for any organisation wanting to deal with information system (IS) security. However, IS security risk management (ISSRM) remains a difficult process to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with enterprise architecture management (EAM) contributes to deal with these issues. A first step towards a better integration of both domains is to define an integrated EAM-ISSRM conceptual model. This paper is about the elaboration and validation of this model. To do so, we improve an existing ISSRM domain model, i.e. a conceptual model depicting the domain of ISSRM, with the concepts of EAM. The validation of the EAM-ISSRM integrated model is then performed with the help of a validation group assessing the utility and usability of the model.
机译:对于任何希望处理信息系统(IS)安全性的组织而言,如今,风险管理已成为主要的指导工具。但是,IS安全风险管理(ISSRM)仍然是建立和维护困难的过程,主要是在具有复杂且相互关联的IS的多重法规的情况下。我们声称与企业体系结构管理(EAM)的连接有助于解决这些问题。更好地集成这两个域的第一步是定义一个集成的EAM-ISSRM概念模型。本文是关于该模型的详细说明和验证。为此,我们使用EAM概念改进了现有的ISSRM域模型,即描述ISSRM域的概念模型。然后,在评估小组的帮助下评估EAM-ISSRM集成模型的有效性和可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号