A Formal Methodology for Modeling Threats to Enterprise Assets
نویسندگان
چکیده
Enterprises usually execute business processes with the help of Information Technology (IT) services which, in turn, are realized by IT assets. Enterprise IT assets contain vulnerabilities that can be exploited by threats to cause harm to business processes and breach security of information assets. Hence, detection of threats is crucial for ensuring business continuity and protection of enterprise information security. Existing threat detection mechanisms are limited in scope owing to absence of methodologies for modeling different categories of threats uniformly. This paper presents a formal methodology that can model diverse types of threats to enterprise assets. The methodology provides sufficient flexibility to enterprises for defining threshold values of threat parameters that suit their specific needs and help them to compute probability of occurrence of threats.
منابع مشابه
An Investigation into Credit Receipt and Enterprise Performance among Small Scale Agro Based Enterprises in the Niger Delta Region of Nigeria
The study was designed to analyze credit receipt and enterprise performance by small scale agro based enterprises in the Niger Delta region of Nigeria. A multistage sampling technique was adopted in selecting 264 agro based enterprises and 96 agro based enterprises that accessed informal and formal credit respectively. The Heckman model was used to examine the factors affecting amount of inform...
متن کاملConceptModeller: a Graph-Based Semantic Modeling Tool for Building Enterprise Applications
The paper outlines semantic-oriented methodology of enterprise software development. The methodology provides integrated visual semantic-oriented enterprise software development and integration in globally distributed heterogeneous environment. The ConceptModeller CASE tool fills the gap between formal computer science models and software engineering practices. The toolkit transforms frame-base...
متن کاملBusiness Process Modeling and Design: AI Models and Methodology
We present a formal framework for representing enterprise knowledge. The framework is largely based on ideas from AI and its concepts (objectives and goals, roles and actors, actions and processes, responsibilities and constraints) allow business analysts to capture knowledge about an enterprise in an intuitive and formal way. We also present a methodology which allows business analysts to go f...
متن کاملA Formal Model for Business Process Modeling and Design
We present a formal framework for representing enterprise knowledge The concepts of our framework objectives and goals roles and actors actions and processes responsibilities and constraints allow business analysts to capture enterprise knowledge in a way that is both intuitive and mathematically formal We also outline the basic steps of a methodology that allows business analysts to produce de...
متن کاملQuantification, Optimization and Uncertainty Modeling in Information Security Risks: A Matrix-Based Approach
In this article, the authors present a quantitative model for estimating security risk exposure for a firm. The model includes a formulation for the optimization of controls as well as determining sensitivity of the exposure of assets to different threats. The model uses a series of matrices to organize the data as groups of assets, vulnerabilities, threats, and controls. The matrices are then ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2014