安全应用程序的同心监督:一种新的安全管理范式

P. Hyland, R. Sandhu
{"title":"安全应用程序的同心监督:一种新的安全管理范式","authors":"P. Hyland, R. Sandhu","doi":"10.1109/CSAC.1998.738575","DOIUrl":null,"url":null,"abstract":"This paper questions the status quo regarding security management (SM) tools that function in an isolated, monolithic fashion. People work best by interacting with others and with their systems to see the \"big picture\" to interpret individual events. Our view of SM called concentric supervision of security applications (CSSA) is a continuous cycle of information flow. CSSA processing of status information and control of security features does not replace existing notions. It serves to enhance the existing ad hoc and segmented \"engineered\" solutions so that SM systems support \"the way people work\". We divide management functions into three phases: administration, operations, and assessment. Different skills, authority, and data are needed to perform tasks in each phase, but some information must flow for efficient and effective functionality. We give suggestions on some linkages by describing typical SM scenarios and how they might function. Parallels are drawn with related issues in network management systems and relationships to current management approaches are discussed.","PeriodicalId":426526,"journal":{"name":"Proceedings 14th Annual Computer Security Applications Conference (Cat. No.98EX217)","volume":"35 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1998-12-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Concentric supervision of security applications: a new security management paradigm\",\"authors\":\"P. Hyland, R. Sandhu\",\"doi\":\"10.1109/CSAC.1998.738575\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper questions the status quo regarding security management (SM) tools that function in an isolated, monolithic fashion. People work best by interacting with others and with their systems to see the \\\"big picture\\\" to interpret individual events. Our view of SM called concentric supervision of security applications (CSSA) is a continuous cycle of information flow. CSSA processing of status information and control of security features does not replace existing notions. It serves to enhance the existing ad hoc and segmented \\\"engineered\\\" solutions so that SM systems support \\\"the way people work\\\". We divide management functions into three phases: administration, operations, and assessment. Different skills, authority, and data are needed to perform tasks in each phase, but some information must flow for efficient and effective functionality. We give suggestions on some linkages by describing typical SM scenarios and how they might function. Parallels are drawn with related issues in network management systems and relationships to current management approaches are discussed.\",\"PeriodicalId\":426526,\"journal\":{\"name\":\"Proceedings 14th Annual Computer Security Applications Conference (Cat. No.98EX217)\",\"volume\":\"35 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"1998-12-07\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings 14th Annual Computer Security Applications Conference (Cat. No.98EX217)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CSAC.1998.738575\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings 14th Annual Computer Security Applications Conference (Cat. No.98EX217)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSAC.1998.738575","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

本文对安全管理(SM)工具的现状提出了质疑,这些工具以孤立的、整体的方式运行。人们通过与他人和他们的系统互动来看到“大局”来解释个别事件,从而工作得最好。我们将SM称为安全应用的同心监督(CSSA),它是信息流的连续循环。CSSA对状态信息的处理和安全特性的控制并不能取代现有的概念。它的作用是增强现有的特别的和分段的“工程”解决方案,使SM系统支持“人们工作的方式”。我们将管理职能分为三个阶段:行政、运营和评估。在每个阶段执行任务需要不同的技能、权限和数据,但是为了实现高效和有效的功能,必须传递一些信息。我们通过描述典型的SM场景及其可能的功能给出了一些联系的建议。与网络管理系统中的相关问题以及与当前管理方法的关系进行了讨论。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Concentric supervision of security applications: a new security management paradigm
This paper questions the status quo regarding security management (SM) tools that function in an isolated, monolithic fashion. People work best by interacting with others and with their systems to see the "big picture" to interpret individual events. Our view of SM called concentric supervision of security applications (CSSA) is a continuous cycle of information flow. CSSA processing of status information and control of security features does not replace existing notions. It serves to enhance the existing ad hoc and segmented "engineered" solutions so that SM systems support "the way people work". We divide management functions into three phases: administration, operations, and assessment. Different skills, authority, and data are needed to perform tasks in each phase, but some information must flow for efficient and effective functionality. We give suggestions on some linkages by describing typical SM scenarios and how they might function. Parallels are drawn with related issues in network management systems and relationships to current management approaches are discussed.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信