A Layered Trust Information Security Architecture

نویسندگان

  • Robson de Oliveira Albuquerque
  • L. Javier García-Villalba
  • Ana Lucila Sandoval Orozco
  • Fábio Buiati
  • Tai-Hoon Kim
چکیده

Information can be considered the most important asset of any modern organization. Securing this information involves preserving confidentially, integrity and availability, the well-known CIA triad. In addition, information security is a risk management job; the task is to manage the inherent risks of information disclosure. Current information security platforms do not deal with the different facets of information technology. This paper presents a layered trust information security architecture (TISA) and its creation was motivated by the need to consider information and security from different points of view in order to protect it. This paper also extends and discusses security information extensions as a way of helping the CIA triad. Furthermore, this paper suggests information representation and treatment elements, operations and support components that can be integrated to show the various risk sources when dealing with both information and security. An overview of how information is represented and treated nowadays in the technological environment is shown, and the reason why it is so difficult to guarantee security in all aspects of the information pathway is discussed.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Access Control for Cross-Organisational Web Service Composition

Service Oriented Architectures (SOA) promise a flexible approach to utilize distributed capabilities that may be located in independent trust domains. These capabilities can be exposed using Web Service technologies, which provide functionality to describe, discover, and invoke exposed services across organisational boundaries. A broad range of SOA-platforms and toolkits are available focusing ...

متن کامل

Scaling Secure Group Communication Systems: Beyond Peer-to-Peer

This paper proposes several integrated security architecture designs for client-server group communication systems. In an integrated architecture, security services are implemented in servers, in contrast to a layered architecture where the same services are implemented in clients. We discuss the performance and accompanying trust issues of each proposed architecture and present experimental re...

متن کامل

Three-Tier Security Model for E-Business: Building Trust and Security for Internet Banking Services

The biggest problem facing Internet banking today is the thorny issues of trust and security of online transactions. In fact, the vast majority of customers are concerned about the safety of their transaction, and they can’t simply trust the web fearing that their transactions and credentials might not be safe due to the increasing number of online Internet attacks. A new model for processing I...

متن کامل

An Open Trusted Computing Architecture — Secure Virtual Machines Enabling User-Defined Policy Enforcement

Virtualization of computers enables a wide variety of applications ranging from server consolidation to secure sandboxing of malicious content. Today, lack of security of virtual machines is a major obstacle for broad adoption of virtual machine technology. We address this obstacle by an open architecture that adds scalable trusted computing concepts to a virtual machine infrastructure. The pla...

متن کامل

An Efficient Framework for Information Security in Cloud Computing Using Auditing Algorithm Shell (AAS)

There is a dynamic escalation and extension in the new infrastructure, educating personnel and licensing new computer programs in the field of IT, due to the emergence of Cloud Computing (CC) paradigm. It has become a quick growing segment of IT business in last couple of years. However, due to the rapid growth of data, people and IT firms, the issue of information security is getting more comp...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره 14  شماره 

صفحات  -

تاریخ انتشار 2014