{"title":"Adaptive information security and privacy","authors":"B. Nuseibeh","doi":"10.1109/RCIS.2017.7956510","DOIUrl":null,"url":null,"abstract":"Although security and privacy by design underpin effective engineering of software intensive systems, the dynamic reality of modern information systems means that such systems are the subject of changes of many different forms that can affect their operational environment, their behaviour, and the behaviour of their users, both legitimate and malicious. Systems must therefore be adaptive by design, in order to adapt effectively at runtime. In particular, these systems must be able to adapt their security and privacy controls, both proactively or in response to a variety of changes in their environment, in the threats they face, and in the assets they are required to protect. This talks presents both empirical and engineering challenges to achieving adaptive security and privacy in information systems. Acknowledging that information systems are increasingly both socio-technical and cyber-physical, the talk explores the impact of cyber-physical-social boundaries and their effective management when engineering secure, privacy-aware, and forensics-ready systems.","PeriodicalId":193156,"journal":{"name":"2017 11th International Conference on Research Challenges in Information Science (RCIS)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 11th International Conference on Research Challenges in Information Science (RCIS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RCIS.2017.7956510","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Although security and privacy by design underpin effective engineering of software intensive systems, the dynamic reality of modern information systems means that such systems are the subject of changes of many different forms that can affect their operational environment, their behaviour, and the behaviour of their users, both legitimate and malicious. Systems must therefore be adaptive by design, in order to adapt effectively at runtime. In particular, these systems must be able to adapt their security and privacy controls, both proactively or in response to a variety of changes in their environment, in the threats they face, and in the assets they are required to protect. This talks presents both empirical and engineering challenges to achieving adaptive security and privacy in information systems. Acknowledging that information systems are increasingly both socio-technical and cyber-physical, the talk explores the impact of cyber-physical-social boundaries and their effective management when engineering secure, privacy-aware, and forensics-ready systems.