A Conceptual Model for Information Security Risk Considering Business Process Perspective

Eva Hariyanti, A. Djunaidy, D. Siahaan
{"title":"A Conceptual Model for Information Security Risk Considering Business Process Perspective","authors":"Eva Hariyanti, A. Djunaidy, D. Siahaan","doi":"10.1109/ICSTC.2018.8528678","DOIUrl":null,"url":null,"abstract":"Information security risk assessment (ISRA) and modeling has become a prominent topic in the last decade. ISRA methods have been developed by many researchers, showing that this issue is always on the lookout for review. Business process is a new perspective in ISRA domain. In this perspective, risk assessment is based on business processes rather than organization's assets. This research is aimed to conduct a systematic review of the ISRA model developed in recent years. Research papers from 2010 to 2017 were selected and examined in the context of information security risk assessment, modeling, and its relationship with business process management. In addition to the current taxonomy, new aspects were added to analyze these papers, i.e. risk context, adaptive ability, and model purpose. Based on analysis results, two research gaps in information security risk modeling were found. First, risk model should have comprehensive assessment method that considers vulnerability propagation and resource valuation in different resources level. Second, risk model should also be able to adapt to business process changes. In this paper, research challenges faced with respect to such issues are outlined and a new conceptual model for ISRA is proposed.","PeriodicalId":196768,"journal":{"name":"2018 4th International Conference on Science and Technology (ICST)","volume":"306 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 4th International Conference on Science and Technology (ICST)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSTC.2018.8528678","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8

Abstract

Information security risk assessment (ISRA) and modeling has become a prominent topic in the last decade. ISRA methods have been developed by many researchers, showing that this issue is always on the lookout for review. Business process is a new perspective in ISRA domain. In this perspective, risk assessment is based on business processes rather than organization's assets. This research is aimed to conduct a systematic review of the ISRA model developed in recent years. Research papers from 2010 to 2017 were selected and examined in the context of information security risk assessment, modeling, and its relationship with business process management. In addition to the current taxonomy, new aspects were added to analyze these papers, i.e. risk context, adaptive ability, and model purpose. Based on analysis results, two research gaps in information security risk modeling were found. First, risk model should have comprehensive assessment method that considers vulnerability propagation and resource valuation in different resources level. Second, risk model should also be able to adapt to business process changes. In this paper, research challenges faced with respect to such issues are outlined and a new conceptual model for ISRA is proposed.
基于业务流程视角的信息安全风险概念模型
近十年来,信息安全风险评估与建模已成为一个突出的课题。许多研究人员已经开发出了ISRA方法,这表明这个问题一直在等待审查。业务流程是ISRA领域的一个新的视角。从这个角度来看,风险评估是基于业务流程而不是组织的资产。本研究旨在对近年来发展起来的ISRA模型进行系统回顾。在信息安全风险评估、建模及其与业务流程管理关系的背景下,选择并审查了2010年至2017年的研究论文。在现有分类方法的基础上,增加了风险背景、适应能力、模型目的等方面的分析。根据分析结果,发现了信息安全风险建模的两个研究空白。首先,风险模型应具有综合的评估方法,考虑不同资源级别的漏洞传播和资源评估。其次,风险模型还应该能够适应业务流程的变化。本文概述了这些问题面临的研究挑战,并提出了一个新的ISRA概念模型。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信