A Study of Security Policy Making Adaptable to Users' Environments Based on International Standards
نویسندگان
چکیده
The security information can be understood like the capability of the information system to resist all the accidents or deliberate actions, with Evaluation Assurance Levels (EAL)[1] as defined in international standards ISO/IEC 15408. These put in danger of the availability, integrity, and confidentiality of stored or transmitted data and the corresponding services that these networks and systems offer or make accessible. In this paper, we propose a security policy making flexibly adaptable to users’ environments to defend them against the information system environment threats. This proposed model allows a user to select the appropriate policy agile and effectively according to the user’s environment. This threats-policy relationship is based on ISO/IEC TR 15446. At the same time, this model allows the user to select the appropriate systems or products evaluated by Common Criteria (CC) or ISO/IEC 15408.
منابع مشابه
طراحی مدلی برای ارتقای ظرفیت خطمشیگذاری در قوه مجریه کشور
Policy making environments have become more complicated in the past decade due to the change in the relationship between nation and state, the effects of global economy and reliance on technology. That’s why the subject of policy- making capacity has been introduced. In order to explain the aspects of policy-making capacity in the executive power, a model adaptable to the requirements of ...
متن کاملConsidering the Coefficient of Relationship between the Students’ Attitude toward Social Networks Policy making with Social Security Feeling
Abstract:This study aims at measuring the relationship between students‟ attitude toward govern-ment‟s virtual social network policy making with social security feeling, in another word, to which extent social security feeling emphasizing on social networks is determined via users‟ attitude toward government‟s media policy making? Analytical-descriptive method including survey is used in ...
متن کاملA semantic-aware role-based access control model for pervasive computing environments
Access control in open and dynamic Pervasive Computing Environments (PCEs) is a very complex mechanism and encompasses various new requirements. In fact, in such environments, context information should be used in access control decision process; however, it is not applicable to gather all context information completely and accurately all the time. Thus, a suitable access control model for PCEs...
متن کاملInvestigate the Quality of Social Security Organization Policy-Making on Social Security Pensioners Life Style Changes
This article has been done with aims to investigate impact of the quality of social security organization policy-making on pensioners' life style in that organization in the city of Mahabad and based on the criteria of environmental, Economic, Social, Political, Health, Personal security, life expectancy, housing and other services have been research case that are the most important factors tha...
متن کاملA context-sensitive dynamic role-based access control model for pervasive computing environments
Resources and services are accessible in pervasive computing environments from anywhere and at any time. Also, due to ever-changing nature of such environments, the identity of users is unknown. However, users must be able to access the required resources based on their contexts. These and other similar complexities necessitate dynamic and context-aware access control models for such environmen...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2005