An ontology-based approach to information systems security management

被引:0
|
作者
Tsoumas, B [1 ]
Dritsas, S [1 ]
Gritzalis, D [1 ]
机构
[1] Athens Univ Econ & Business, Dept Informat, GR-10434 Athens, Greece
来源
关键词
security management; security policy; IS security; security ontology;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Complexity of modem information systems (IS), impose novel security requirements. On the other hand, the ontology paradigm aims to support knowledge sharing and reuse in an explicit and mutually agreed manner. Therefore, in this paper we set the foundations for establishing a knowledge-based, ontology-centric framework with respect to the security management of an arbitrary IS. We demonstrate that the linking between high-level policy statements and deployable security controls is possible and the implementation is achievable. This framework may support critical security expert activities with respect to security requirements identification and selection of certain controls and countermeasures. In addition, we present a structured approach for establishing a security management framework and identify its critical parts. Our security ontology is being represented in a neutral manner, based on well-known security standards, extending widely used information systems modeling approaches.
引用
收藏
页码:151 / 164
页数:14
相关论文
共 50 条
  • [21] The Information Systems Modeling with an Ontology-Based ERD
    Luo, Dershing
    PACIFIC ASIA CONFERENCE ON INFORMATION SYSTEMS 2005, SECTIONS 1-8 AND POSTER SESSIONS 1-6, 2005, : 1447 - 1455
  • [22] An Ontology-Based Record Management Systems Approach for Enhancing Decision Support
    Samsudin, Ahmad Z. H.
    McGrath, G. Michael
    Miah, Shah J.
    AMCIS 2014 PROCEEDINGS, 2014,
  • [23] An Ontology Based Approach to Information Security
    Pereira, Teresa
    Santos, Henrique
    METADATA AND SEMANTIC RESEARCH, PROCEEDINGS, 2009, 46 : 183 - 192
  • [24] An ontology-based approach for Product Lifecycle Management
    Matsokis, Aristeidis
    Kiritsis, Dimitris
    COMPUTERS IN INDUSTRY, 2010, 61 (08) : 787 - 797
  • [25] Towards an Ontology-based Approach for Information Interoperability Between BIM and Facility Management
    Chen, Weiwei
    Chen, Keyu
    Cheng, Jack C. P.
    ADVANCED COMPUTING STRATEGIES FOR ENGINEERING, PT II, 2018, 10864 : 447 - 469
  • [26] Ontology-based Approach to Competence Profile Management
    Tarasov, Vladimir
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2012, 18 (20) : 2893 - 2919
  • [27] A concern-oriented and ontology-based approach to constructing facets of information systems
    Bogdan, Crenguta
    Serbanati, Luca Dan
    ICSOFT 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON SOFTWARE AND DATA TECHNOLOGIES, VOL ISDM/WSEHST/DC, 2007, : 220 - +
  • [28] A logic-based approach for query refinement in ontology-based information retrieval systems
    Stojanovic, N
    Stojanovic, L
    ICTAI 2004: 16TH IEEE INTERNATIONALCONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2004, : 450 - 457
  • [29] Ontology-Based Knowledge Management for Enterprise Systems
    Ahmad, Mohammad
    Zakaria, Nor
    Sedera, Darshana
    INTERNATIONAL JOURNAL OF ENTERPRISE INFORMATION SYSTEMS, 2011, 7 (04) : 64 - 90
  • [30] An Ontology-Based Approach for Geographic Information Retrieval on the Web
    Kun, Mei
    Fuling, Bian
    2007 INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-15, 2007, : 5959 - 5962