An Information Security Management for Socio-Technical Analysis of System Security

被引:0
|
作者
Huynen, Jean-Louis [1 ]
Lenzini, Gabriele [1 ]
机构
[1] Univ Luxembourg, Interdisciplinary Ctr Secur Reliabil & Trust SnT, Esch Sur Alzette, Luxembourg
来源
关键词
Socio-technical security; Information Security Management and Reasoning; Root Cause Analysis;
D O I
10.1007/978-3-319-93354-2_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Concerned about the technical and social aspects at the root causes of security incidents and how they can hide security vulnerabilities we propose a methodology compatible with the Information Security Management life-cycle. Retrospectively, it supports analysts to reason about the socio-technical causes of observed incidents; prospectively, it helps designers account for human factors and remove potential socio-technical vulnerabilities from a system's design. The methodology, called S.CREAM, stems from practices in safety, but because of key differences between the two disciplines migrating concepts, techniques, and tools from safety to security requires a complete re-thinking. S.CREAM is supported by a tool, which we implemented. When available online it will assist security analysts and designers in their tasks. Using S.CREAM, we discuss potential socio-technical issues in the Yubikey's two-factor authentication device.
引用
收藏
页码:222 / 251
页数:30
相关论文
共 50 条
  • [1] A Socio-Technical Approach to Information Security
    Mujinga, Mathias
    Eloff, Mariki M.
    Kroeze, Jan H.
    AMCIS 2017 PROCEEDINGS, 2017,
  • [2] Modelling the Enemies of an IT Security System - A Socio-Technical System Security Model
    Kowalski, Stewart
    Mwakalinga, Jeffy
    IMCIC'11: THE 2ND INTERNATIONAL MULTI-CONFERENCE ON COMPLEXITY, INFORMATICS AND CYBERNETICS, VOL I, 2011, : 251 - 256
  • [3] From Situation Awareness to Action: An Information Security Management Toolkit for Socio-technical Security Retrospective and Prospective Analysis
    Huynen, Jean-Louis
    Lenzini, Gabriele
    ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 213 - 224
  • [4] Security analysis of socio-technical physical systems
    Lenzini, Gabriele
    Mauw, Sjouke
    Ouchani, Samir
    COMPUTERS & ELECTRICAL ENGINEERING, 2015, 47 : 258 - 274
  • [5] A Framework and Prototype for A Socio-Technical Security Information and Event Management System (ST-SIEM)
    AlSabbagh, Bilal
    Kowalski, Stewart
    2016 EUROPEAN INTELLIGENCE AND SECURITY INFORMATICS CONFERENCE (EISIC), 2016, : 192 - 195
  • [6] Holistic security requirements analysis for socio-technical systems
    Li, Tong
    Horkoff, Jennifer
    Mylopoulos, John
    SOFTWARE AND SYSTEMS MODELING, 2018, 17 (04): : 1253 - 1285
  • [7] A Socio-Technical Methodology for the Security and Privacy Analysis of Services
    Bella, Giampaolo
    Curzon, Paul
    Giustolisi, Rosario
    Lenzini, Gabriele
    2014 38TH ANNUAL IEEE INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSACW 2014), 2014, : 401 - 406
  • [8] Holistic security requirements analysis for socio-technical systems
    Tong Li
    Jennifer Horkoff
    John Mylopoulos
    Software & Systems Modeling, 2018, 17 : 1253 - 1285
  • [9] A Socio-Technical Investigation into Smartphone Security
    Volkamer, Melanie
    Renaud, Karen
    Kulyk, Oksana
    Emeroez, Sinem
    SECURITY AND TRUST MANAGEMENT (STM 2015), 2015, 9331 : 265 - 273
  • [10] Modelling Static and Dynamic Aspects of Security: A Socio-Technical View on Information Security Metrics
    Kowalski, Stewart
    Barabanov, Rostyslav
    IMCIC'11: THE 2ND INTERNATIONAL MULTI-CONFERENCE ON COMPLEXITY, INFORMATICS AND CYBERNETICS, VOL I, 2011, : 246 - 250