可互操作组织的安全性和隐私性

A. Correia, Pedro B. Água, Armindo Frias, M. Simões-Marques
{"title":"可互操作组织的安全性和隐私性","authors":"A. Correia, Pedro B. Água, Armindo Frias, M. Simões-Marques","doi":"10.54941/ahfe1003609","DOIUrl":null,"url":null,"abstract":"There are organizations for whom interoperability is crucial for the accomplishment of their mission, such as in the areas of disaster management, security, and defense. However, those organizations also must comply with the constraints and rules for information security and privacy. The ISO 27001 provides a global standard framework to help organizations to protect their information in a systematic way, through the adoption of an information security management system. Furthermore, the ISO 27701, provides specific data privacy controls, allowing the organization to demonstrate effective privacy data management. A challenge organizations face is how to comply with information security and privacy policies and procedures together with the accomplishment of their mission. In this paper, we argue this can be achieved with an Enterprise Architecture (EA) framework. Particularly, the NATO Architecture Framework (NAF) provides a methodology to develop EA artifacts, however it lacks the tools amenable to enforce information security and privacy. In this paper, we propose the integration of ISO 27001 and ISO 27701 in NAF, in order that the EA artifacts delivered by NAF framework, could have embedded the information security and privacy principles by design.","PeriodicalId":402751,"journal":{"name":"Human Factors and Systems Interaction","volume":"143 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Security and privacy for interoperable organizations\",\"authors\":\"A. Correia, Pedro B. Água, Armindo Frias, M. Simões-Marques\",\"doi\":\"10.54941/ahfe1003609\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"There are organizations for whom interoperability is crucial for the accomplishment of their mission, such as in the areas of disaster management, security, and defense. However, those organizations also must comply with the constraints and rules for information security and privacy. The ISO 27001 provides a global standard framework to help organizations to protect their information in a systematic way, through the adoption of an information security management system. Furthermore, the ISO 27701, provides specific data privacy controls, allowing the organization to demonstrate effective privacy data management. A challenge organizations face is how to comply with information security and privacy policies and procedures together with the accomplishment of their mission. In this paper, we argue this can be achieved with an Enterprise Architecture (EA) framework. Particularly, the NATO Architecture Framework (NAF) provides a methodology to develop EA artifacts, however it lacks the tools amenable to enforce information security and privacy. In this paper, we propose the integration of ISO 27001 and ISO 27701 in NAF, in order that the EA artifacts delivered by NAF framework, could have embedded the information security and privacy principles by design.\",\"PeriodicalId\":402751,\"journal\":{\"name\":\"Human Factors and Systems Interaction\",\"volume\":\"143 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"1900-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Human Factors and Systems Interaction\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.54941/ahfe1003609\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Human Factors and Systems Interaction","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.54941/ahfe1003609","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

对于某些组织来说,互操作性对于完成其任务至关重要,例如在灾难管理、安全和防御领域。然而,这些组织还必须遵守信息安全和隐私的约束和规则。ISO 27001提供了一个全球标准框架,通过采用信息安全管理体系,帮助组织以系统的方式保护其信息。此外,ISO 27701提供了具体的数据隐私控制,允许组织展示有效的隐私数据管理。组织面临的挑战是如何在完成其使命的同时遵守信息安全和隐私政策和程序。在本文中,我们认为这可以通过企业架构(EA)框架来实现。特别是,NATO架构框架(NAF)提供了一种开发EA工件的方法,但是它缺乏执行信息安全和隐私的工具。在本文中,我们建议在NAF中集成ISO 27001和ISO 27701,以便由NAF框架交付的EA工件可以通过设计嵌入信息安全和隐私原则。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Security and privacy for interoperable organizations
There are organizations for whom interoperability is crucial for the accomplishment of their mission, such as in the areas of disaster management, security, and defense. However, those organizations also must comply with the constraints and rules for information security and privacy. The ISO 27001 provides a global standard framework to help organizations to protect their information in a systematic way, through the adoption of an information security management system. Furthermore, the ISO 27701, provides specific data privacy controls, allowing the organization to demonstrate effective privacy data management. A challenge organizations face is how to comply with information security and privacy policies and procedures together with the accomplishment of their mission. In this paper, we argue this can be achieved with an Enterprise Architecture (EA) framework. Particularly, the NATO Architecture Framework (NAF) provides a methodology to develop EA artifacts, however it lacks the tools amenable to enforce information security and privacy. In this paper, we propose the integration of ISO 27001 and ISO 27701 in NAF, in order that the EA artifacts delivered by NAF framework, could have embedded the information security and privacy principles by design.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信