Towards an integrated risk analysis security framework according to a systematic analysis of existing proposals

被引:1
|
作者
Santos-Olmo, Antonio [1 ,2 ]
Sanchez, Luis Enrique [1 ,2 ]
Rosado, David G. [1 ]
Serrano, Manuel A. [3 ]
Blanco, Carlos [4 ]
Mouratidis, Haralambos [2 ]
Fernandez-Medina, Eduardo [1 ]
机构
[1] Univ Castilla La Mancha, GSyA Res Grp, Ciudad Real 13071, Spain
[2] Univ Essex, Inst Analyt & Data Sci, Colchester CO4 3SQ, England
[3] Univ Castilla La Mancha, Alarcos Res Grp, Ciudad Real 13071, Spain
[4] Univ Cantabria, Dept Comp Sci & Elect, ISTR Res Grp, Santander 39005, Spain
基金
欧盟地平线“2020”;
关键词
information security management; security system; security risk assessment and management; MANAGEMENT; CULTURE; METHODOLOGY; INTERNET;
D O I
10.1007/s11704-023-1582-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The information society depends increasingly on risk assessment and management systems as means to adequately protect its key information assets. The availability of these systems is now vital for the protection and evolution of companies. However, several factors have led to an increasing need for more accurate risk analysis approaches. These are: the speed at which technologies evolve, their global impact and the growing requirement for companies to collaborate. Risk analysis processes must consequently adapt to these new circumstances and new technological paradigms. The objective of this paper is, therefore, to present the results of an exhaustive analysis of the techniques and methods offered by the scientific community with the aim of identifying their main weaknesses and providing a new risk assessment and management process. This analysis was carried out using the systematic review protocol and found that these proposals do not fully meet these new needs. The paper also presents a summary of MARISMA, the risk analysis and management framework designed by our research group. The basis of our framework is the main existing risk standards and proposals, and it seeks to address the weaknesses found in these proposals. MARISMA is in a process of continuous improvement, as is being applied by customers in several European and American countries. It consists of a risk data management module, a methodology for its systematic application and a tool that automates the process.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] Towards an integrated risk analysis security framework according to a systematic analysis of existing proposals
    Antonio Santos-Olmo
    Luis Enrique Sánchez
    David G. Rosado
    Manuel A. Serrano
    Carlos Blanco
    Haralambos Mouratidis
    Eduardo Fernández-Medina
    [J]. Frontiers of Computer Science, 2024, 18
  • [2] Basis for an integrated security ontology according to a systematic review of existing proposals
    Blanco, Carlos
    Lasheras, Joaquin
    Fernandez-Medina, Eduardo
    Valencia-Garcia, Rafael
    Toval, Ambrosio
    [J]. COMPUTER STANDARDS & INTERFACES, 2011, 33 (04) : 372 - 388
  • [3] Integrated framework for dynamic security analysis
    Kumar, ABR
    Brandwajn, V
    Ipakchi, A
    Adapa, R
    [J]. IEEE TRANSACTIONS ON POWER SYSTEMS, 1998, 13 (03) : 816 - 821
  • [4] Integrated framework for dynamic security analysis
    ABB Systems Control Co Inc, Santa Clara, United States
    [J]. IEEE Trans Power Syst, 3 (816-821):
  • [5] Integrated framework for dynamic security analysis
    Kumar, ABR
    Brandwajn, V
    Ipakchi, A
    Adapa, R
    [J]. PROCEEDINGS OF THE 20TH INTERNATIONAL CONFERENCE ON POWER INDUSTRY COMPUTER APPLICATIONS, 1996, : 260 - 265
  • [6] TOWARDS AN INTEGRATED FRAMEWORK OF DATA ANALYSIS
    Glaser, Ezra
    [J]. MANAGEMENT SCIENCE, 1955, 1 (02) : 173 - 176
  • [7] Towards an integrated formal analysis for security and trust
    Martinelli, F
    [J]. FORMAL METHODS FOR OPEN OBJECT-BASED DISTRIBUTED SYSTEMS, PROCEEDINGS, 2005, 3535 : 115 - 130
  • [8] Building an integrated requirements engineering process based on Intelligent Systems and Semantic Reasoning on the basis of a systematic analysis of existing proposals
    Corral, Alexandra
    Sanchez, Luis E.
    Antonelli, Leandro
    [J]. JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2022, 28 (11) : 1136 - 1168
  • [9] Towards a Framework to Measure Security Expertise in Requirements Analysis
    Hibshi, Hanan
    Breaux, Travis
    Riaz, Maria
    Williams, Laurie
    [J]. 2014 IEEE 1ST WORKSHOP ON EVOLVING SECURITY AND PRIVACY REQUIREMENTS ENGINEERING (ESPRE), 2014, : 13 - 18
  • [10] Integrated Network and Security Operation Center: A Systematic Analysis
    Shahjee, Deepesh
    Ware, Nilesh
    [J]. IEEE ACCESS, 2022, 10 : 27881 - 27898