Design and Implementation of a Comprehensive Information Security Risk Management Tool based on Multi-agents Systems

M. Ghazouani, H. Medromi, L. Moussaid
{"title":"Design and Implementation of a Comprehensive Information Security Risk Management Tool based on Multi-agents Systems","authors":"M. Ghazouani, H. Medromi, L. Moussaid","doi":"10.5120/IJAIS2017451711","DOIUrl":null,"url":null,"abstract":"While there are many framework that help users in Governance, Risk, and Compliance (GRC), we know of none which actually try to automate the process by using multi agent systems. The Team of Systems’ Architecture proposes an integrated IT GRC architecture for a high level IT GRC management. This article focuses on IT Risk topic and presents a new approach for a multi-agent expert system, where managers of IT GRC can in an intelligent manner specify the IT needs following the strategic directives through a questionnaire about specific business goals. The key element that differentiates this research from the previous ones is that none of them are based on multi-agents system. The system was verified on concrete example. Future works consists on realizing a practical example of the proposed subsystem on real company systems that are involved in the research in order to overcomes obstacles and achieve IT organization objectives. General Terms Security risk assessment, risk management system, information system","PeriodicalId":92376,"journal":{"name":"International journal of applied information systems","volume":"18 1","pages":"1-8"},"PeriodicalIF":0.0000,"publicationDate":"2017-10-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal of applied information systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5120/IJAIS2017451711","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

While there are many framework that help users in Governance, Risk, and Compliance (GRC), we know of none which actually try to automate the process by using multi agent systems. The Team of Systems’ Architecture proposes an integrated IT GRC architecture for a high level IT GRC management. This article focuses on IT Risk topic and presents a new approach for a multi-agent expert system, where managers of IT GRC can in an intelligent manner specify the IT needs following the strategic directives through a questionnaire about specific business goals. The key element that differentiates this research from the previous ones is that none of them are based on multi-agents system. The system was verified on concrete example. Future works consists on realizing a practical example of the proposed subsystem on real company systems that are involved in the research in order to overcomes obstacles and achieve IT organization objectives. General Terms Security risk assessment, risk management system, information system
基于多agent系统的综合信息安全风险管理工具的设计与实现
虽然有许多框架可以帮助用户进行治理、风险和遵从(GRC),但据我们所知,没有一个框架真正尝试通过使用多代理系统来自动化流程。系统架构团队提出了一个集成的IT GRC架构,用于高层次的IT GRC管理。本文主要关注IT风险主题,并提出了一种多代理专家系统的新方法,其中IT GRC的管理人员可以通过关于特定业务目标的问卷调查,以智能的方式根据战略指示指定IT需求。本研究与以往研究的关键区别在于它们都不是基于多智能体系统。通过实例验证了该系统的有效性。未来的工作包括在研究中涉及的真实公司系统上实现所提出的子系统的实际示例,以克服障碍并实现IT组织目标。安全风险评估,风险管理系统,信息系统
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信