Automation of risk management processes

M. Šterbák, P. Segec, Ján Jurč
{"title":"Automation of risk management processes","authors":"M. Šterbák, P. Segec, Ján Jurč","doi":"10.1109/ICETA54173.2021.9726596","DOIUrl":null,"url":null,"abstract":"Information technology and computing, such as computers, printers, network devices, cloud storage, cloud services and, last but not least, application software, are an integral part of any organization. These information assets are key to the organization, and it is therefore essential that they adhere to three aspects of information security. Namely availability, integrity, and confidentiality. Security, as well as these three aspects, is addressed by information security management, which is defined in ISO 2700x standards. According to these standards, security is dedicated to the planning, implementation, control and subsequent monitoring and improvement of the information security management system. To successfully secure a system, it is necessary to know what and to what extent we want to secure. In order for this to be possible, it is necessary to take steps to identify and assess information assets, as well as to identify and assess risks. Based on the information obtained, it is then possible to create security policies and define countermeasures to reduce security risks. However, the information security risk management is a costly, demanding and complex activity. There are some possibilities how to automate and improve the process of identifying and assessing risks, but the first step in the whole process is always the identification of information assets. And this is still largely done manually and at length, based on available resources. In this article, we will provide a description of individual subprocesses of information security risk management and we identify the possibilities of applying automation to individual subprocesses and their interconnection to a complex information system.","PeriodicalId":194572,"journal":{"name":"2021 19th International Conference on Emerging eLearning Technologies and Applications (ICETA)","volume":"69 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-11-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 19th International Conference on Emerging eLearning Technologies and Applications (ICETA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICETA54173.2021.9726596","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Information technology and computing, such as computers, printers, network devices, cloud storage, cloud services and, last but not least, application software, are an integral part of any organization. These information assets are key to the organization, and it is therefore essential that they adhere to three aspects of information security. Namely availability, integrity, and confidentiality. Security, as well as these three aspects, is addressed by information security management, which is defined in ISO 2700x standards. According to these standards, security is dedicated to the planning, implementation, control and subsequent monitoring and improvement of the information security management system. To successfully secure a system, it is necessary to know what and to what extent we want to secure. In order for this to be possible, it is necessary to take steps to identify and assess information assets, as well as to identify and assess risks. Based on the information obtained, it is then possible to create security policies and define countermeasures to reduce security risks. However, the information security risk management is a costly, demanding and complex activity. There are some possibilities how to automate and improve the process of identifying and assessing risks, but the first step in the whole process is always the identification of information assets. And this is still largely done manually and at length, based on available resources. In this article, we will provide a description of individual subprocesses of information security risk management and we identify the possibilities of applying automation to individual subprocesses and their interconnection to a complex information system.
风险管理过程的自动化
信息技术和计算,如计算机、打印机、网络设备、云存储、云服务,以及最后但并非最不重要的应用软件,是任何组织的一个组成部分。这些信息资产是组织的关键,因此它们必须遵守信息安全的三个方面。即可用性、完整性和机密性。ISO 2700x标准对信息安全管理进行了定义,以解决安全问题以及这三个方面的问题。根据这些标准,安全致力于信息安全管理体系的策划、实施、控制以及后续的监视和改进。为了成功地保护一个系统,有必要知道我们想要保护什么以及保护到什么程度。为了实现这一点,有必要采取步骤来识别和评估信息资产,以及识别和评估风险。根据获得的信息,可以创建安全策略并定义对策以降低安全风险。然而,信息安全风险管理是一项成本高、要求高且复杂的活动。如何自动化和改进识别和评估风险的过程有一些可能性,但整个过程的第一步始终是信息资产的识别。这在很大程度上仍然是基于可用资源的手工和冗长的工作。在本文中,我们将提供信息安全风险管理的各个子过程的描述,并确定将自动化应用于各个子过程及其与复杂信息系统的互连的可能性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信