Enterprise Models as Drivers for IT Security Management at Runtime
نویسندگان
چکیده
This paper describes how enterprise models can be made suitable for monitoring and controlling IT security at runtime. A holistic modeling method is proposed that extends enterprise models with runtime information, turning them into dashboards for managing security incidents and risks, and supporting decision making at runtime. The requirements of such a modeling method are defined and an existing enterprise modeling language is extended with relevant security concepts that also capture runtime information to satisfy these requirements. Subsequently, the resulting modeling method is evaluated against the previously defined requirements. It is also shown that common metamodeling frameworks are not suitable for implementing a modeling environment that results in suitable IT security dashboards. This leads to suggesting implementation of the modeling environment using the eXecutable Modeling Facility.
منابع مشابه
A Proposed Model for Assessing the Determinants of Enterprise Resource Planning Adoption and Satisfaction
The complex information systems such as enterprise resource planning (ERP) systems are essential for organizations to make them competitive. However, the success of ERP system projects is a difficult process as it involves different types of end user assessment. The main objective of the present study is to find the key determinants that open the door to employee satisfaction and adoption of E...
متن کاملToward Comprehensive Security Policy Governance in Collaborative Enterprise
The lack of trust among software services spanning multiple organisations and the rather poor adaptability level of the current security policies are often seen as braking forces to collaborative-enterprise development. Removing this impediment involves re-thinking the security policy according to “due usage” requirements and setting security enforcement and regulations according to both the du...
متن کاملMDSE@R: Model-Driven Security Engineering at Runtime
New security threats arise frequently and impact on enterprise software security requirements. However, most existing security engineering approaches focus on capturing and enforcing security requirements at design time. Many do not address how a system should be adapted to cope with new unanticipated security requirements that arise at runtime. We describe a new approach Model Driven Security ...
متن کاملProviding an Enterprise Architecture Framework Model for Laboratory Information Management Systems by Service Oriented Approach
Background and Aim: Laboratories are one of the most important scientific and research centers. Laboratory information management systems provide a platform for recording the information and collaborating between researchers. The main purpose of this study was suggesting an organizational architecture model of laboratory information management systems. Materials and Methods: This study was a ...
متن کاملStrategic Management of the Innovative Activity of the Enterprise
Effective innovative activity of enterprises with the dynamic economic development is possible under the conditions of timely implementation of innovative projects that satisfy and meet the requirements of the external and internal environment and contribute to building up their own potential with the orientation of the enterprise activity on the long-term prospect of development. This contribu...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013