Information Security Governance Analysis Using Probabilistic Relational Models

نویسندگان

  • Waldo Rocha Flores
  • Mathias Ekstedt
چکیده

The presentation will concern my current research project aiming at developing a Probabilistic Relational Model (PRM) to support analysis of Information Security Governance (ISG) in an organization. The awareness of the important aspects of information security that ISG covers has increased among companies as it provides a holistic approach to protection of organizational assets. ISG considers components such as management commitment, organizational structures, user awareness, policies, processes, and technologies. In order to increase the understanding of the ISG structure and the dependencies between its different components, but also to perform various kinds of analysis, architectural models can be employed. This paper proposes the use of Probabilistic Relational Models (PRM) for analyzing process capability of mitigating information security vulnerabilities. Using the PRM enables inference between different ISG components expressed in probabilities, and also inference on the process capability. A concrete PRM which exemplifies how to govern the Risk process will further be presented, and thus showing how the PRM can be adapted to fit the analysis of a specific process in an organizational environment.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A framework and theory for cyber security assessments

Information system security risk, defined as the product of the monetary losses associated with security incidents and the probability that they occur, is a suitable decision criterion when considering different information system architectures. This paper describes how probabilistic relational models can be used to specify architecture metamodels so that security risk can be inferred from meta...

متن کامل

A probabilistic relational model for security risk analysis

Information system security risk, defined as the product of the monetary losses associated with security incidents and the probability that they occur, is a suitable decision criterion when considering different information system architectures. This paper describes how probabilistic relational models can be used to specify architecture metamodels so that security risk can be inferred from meta...

متن کامل

Critical Success Factors in implementing information security governance (Case study: Iranian Central Oil Fields Company)

The oil industry, as one of the main industries of the country, has always faced cyber attacks and security threats. Therefore, the integration of information security in corporate governance is essential and a governance challenge. The integration of information security and corporate governance is called information security governance. In this research, we identified "critical success factor...

متن کامل

Implementation of Information Technology Governance in the Malaysian Public Sector Practice

The increased dependence on IT and rise of security threats in organisations has led to the awareness of the need for adopting formal IT governance practices. However, how far have organisation came to realise the implementation of these practices is yet unknown at least in the Malaysian context. The article discusses information technology governance practices in public sector agencies from th...

متن کامل

An Optimized Dynamic Process Model of IS Security Governance Implementation

The year 2011 has witnessed a lot of high profiles data breaches despite the availability of IS security and governance controls, frameworks, standards and models for organisations to choose from; and the technical advances made in intrusion prevention and detection. Taking this issue into account the objective of this paper is to identify and analyse the weaknesses in the IS security defences ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011