An ontology-based approach to information systems security management

被引:0
|
作者
Tsoumas, B [1 ]
Dritsas, S [1 ]
Gritzalis, D [1 ]
机构
[1] Athens Univ Econ & Business, Dept Informat, GR-10434 Athens, Greece
来源
关键词
security management; security policy; IS security; security ontology;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Complexity of modem information systems (IS), impose novel security requirements. On the other hand, the ontology paradigm aims to support knowledge sharing and reuse in an explicit and mutually agreed manner. Therefore, in this paper we set the foundations for establishing a knowledge-based, ontology-centric framework with respect to the security management of an arbitrary IS. We demonstrate that the linking between high-level policy statements and deployable security controls is possible and the implementation is achievable. This framework may support critical security expert activities with respect to security requirements identification and selection of certain controls and countermeasures. In addition, we present a structured approach for establishing a security management framework and identify its critical parts. Our security ontology is being represented in a neutral manner, based on well-known security standards, extending widely used information systems modeling approaches.
引用
收藏
页码:151 / 164
页数:14
相关论文
共 50 条
  • [1] An Ontology-Based Security Risk Management Model for Information Systems
    Arogundade, Oluwasefunmi T.
    Abayomi-Alli, Adebayo
    Misra, Sanjay
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2020, 45 (08) : 6183 - 6198
  • [2] An Ontology-Based Security Risk Management Model for Information Systems
    Oluwasefunmi T. Arogundade
    Adebayo Abayomi-Alli
    Sanjay Misra
    Arabian Journal for Science and Engineering, 2020, 45 : 6183 - 6198
  • [3] Ontology-based Decision Support for Information Security Risk Management
    Ekelhart, Andreas
    Fenz, Stefan
    Neubauer, Thomas
    2009 FOURTH INTERNATIONAL CONFERENCE ON SYSTEMS (ICONS), 2009, : 80 - +
  • [4] An Ontology-Based Reuse Approach for Information Systems Engineering
    Ramadour, Philippe
    Cauvet, Corine
    SITIS 2008: 4TH INTERNATIONAL CONFERENCE ON SIGNAL IMAGE TECHNOLOGY AND INTERNET BASED SYSTEMS, PROCEEDINGS, 2008, : 572 - 579
  • [5] Towards an ontology-based security management
    Tsoumas, Bill
    Gritzalis, Dimitris
    20TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 1, PROCEEDINGS, 2006, : 985 - +
  • [6] Ontology-based knowledge management approach for information system development
    Klarin, Karmen
    Celar, Stipo
    2013 21ST TELECOMMUNICATIONS FORUM (TELFOR), 2013, : 805 - +
  • [7] Ontology-based Information Content Security Analysis
    Yan, Pan
    Zhao, Yanping
    Sanxing, Cao
    FIFTH INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS AND KNOWLEDGE DISCOVERY, VOL 5, PROCEEDINGS, 2008, : 479 - +
  • [8] An Ontology-Based Scenario for Teaching the Management of Health Information Systems
    Jahn, Franziska
    Schaaf, Michael
    Kahmann, Christian
    Tahar, Kais
    Kuecherer, Christian
    Paech, Barbara
    Winter, Alfred
    EXPLORING COMPLEXITY IN HEALTH: AN INTERDISCIPLINARY SYSTEMS APPROACH, 2016, 228 : 359 - 363
  • [9] An ontology-based approach for managing and maintaining privacy in information systems
    Abou-Tair, Dhiah el Diehn I.
    Berlik, Stefan
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2006: COOPIS, DOA, GADA, AND ODBAS, PT 1, PROCEEDINGS, 2006, 4275 : 983 - 994
  • [10] An Ontology-Based Approach to Information Retrieval
    Mestrovic, Ana
    Cali, Andrea
    SEMANTIC KEYWORD-BASED SEARCH ON STRUCTURED DATA SOURCES, IKC 2016, 2017, 10151 : 150 - 156