An ontology-based approach to information systems security management

被引:0
|
作者
Tsoumas, B [1 ]
Dritsas, S [1 ]
Gritzalis, D [1 ]
机构
[1] Athens Univ Econ & Business, Dept Informat, GR-10434 Athens, Greece
来源
关键词
security management; security policy; IS security; security ontology;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Complexity of modem information systems (IS), impose novel security requirements. On the other hand, the ontology paradigm aims to support knowledge sharing and reuse in an explicit and mutually agreed manner. Therefore, in this paper we set the foundations for establishing a knowledge-based, ontology-centric framework with respect to the security management of an arbitrary IS. We demonstrate that the linking between high-level policy statements and deployable security controls is possible and the implementation is achievable. This framework may support critical security expert activities with respect to security requirements identification and selection of certain controls and countermeasures. In addition, we present a structured approach for establishing a security management framework and identify its critical parts. Our security ontology is being represented in a neutral manner, based on well-known security standards, extending widely used information systems modeling approaches.
引用
收藏
页码:151 / 164
页数:14
相关论文
共 50 条
  • [41] Ontology-Based Decision Support for Security Management in Heterogeneous Networks
    Choras, Michal
    Kozik, Rafal
    Flizikowski, Adam
    Renk, Rafal
    Holubowicz, Witold
    EMERGING INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS: WITH ASPECTS OF ARTIFICIAL INTELLIGENCE, 2009, 5755 : 920 - +
  • [42] Virtual organization security policies: An ontology-based integration approach
    Muthaiyah, Saravanan
    Kerschberg, Larry
    INFORMATION SYSTEMS FRONTIERS, 2007, 9 (05) : 505 - 514
  • [43] An Ontology-Based Approach for Setting Security Policies in Smart Homes
    Roffarello, Alberto Monge
    De Russis, Luigi
    EMERGING TECHNOLOGIES FOR AUTHORIZATION AND AUTHENTICATION, ETAA 2022, 2023, 13782 : 1 - 14
  • [44] Virtual organization security policies: An ontology-based integration approach
    Saravanan Muthaiyah
    Larry Kerschberg
    Information Systems Frontiers, 2007, 9 : 505 - 514
  • [45] An ontology-based learning approach for automatically classifying security requirements
    Li, Tong
    Chen, Zhishuai
    JOURNAL OF SYSTEMS AND SOFTWARE, 2020, 165
  • [46] User-centric social context information management: an ontology-based approach and platform
    Muhammad Ashad Kabir
    Jun Han
    Jian Yu
    Alan Colman
    Personal and Ubiquitous Computing, 2014, 18 : 1061 - 1083
  • [47] User-centric social context information management: an ontology-based approach and platform
    Kabir, Muhammad Ashad
    Han, Jun
    Yu, Jian
    Colman, Alan
    PERSONAL AND UBIQUITOUS COMPUTING, 2014, 18 (05) : 1061 - 1083
  • [48] An Ontology-based Configurator for Customized Product Information based upon the Slow Intelligence Systems Approach
    Zegarra, Emilio
    Colace, Francesco
    de Santo, Massimo
    Chang, Shi-Kuo
    22ND INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING & KNOWLEDGE ENGINEERING (SEKE 2010), 2010, : 521 - 528
  • [49] An Ontology-Based Approach For Software Architectural Knowledge Management
    Choobdaran, Narges
    Sharfi, Sayed Mehran
    Khayyambashi, Mohamad Reza
    JOURNAL OF MATHEMATICS AND COMPUTER SCIENCE-JMCS, 2014, 11 (02): : 93 - 104
  • [50] An ontology-based approach to knowledge management in design processes
    Brandt, Sebastian C.
    Morbach, Jan
    Miatidis, Michalis
    Theissen, Manfred
    Jarke, Matthias
    Marquardt, Wolfgang
    COMPUTERS & CHEMICAL ENGINEERING, 2008, 32 (1-2) : 320 - 342