An Information Security Management for Socio-Technical Analysis of System Security

被引:0
|
作者
Huynen, Jean-Louis [1 ]
Lenzini, Gabriele [1 ]
机构
[1] Univ Luxembourg, Interdisciplinary Ctr Secur Reliabil & Trust SnT, Esch Sur Alzette, Luxembourg
来源
INFORMATION SYSTEMS SECURITY AND PRIVACY | 2018年 / 867卷
关键词
Socio-technical security; Information Security Management and Reasoning; Root Cause Analysis;
D O I
10.1007/978-3-319-93354-2_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Concerned about the technical and social aspects at the root causes of security incidents and how they can hide security vulnerabilities we propose a methodology compatible with the Information Security Management life-cycle. Retrospectively, it supports analysts to reason about the socio-technical causes of observed incidents; prospectively, it helps designers account for human factors and remove potential socio-technical vulnerabilities from a system's design. The methodology, called S.CREAM, stems from practices in safety, but because of key differences between the two disciplines migrating concepts, techniques, and tools from safety to security requires a complete re-thinking. S.CREAM is supported by a tool, which we implemented. When available online it will assist security analysts and designers in their tasks. Using S.CREAM, we discuss potential socio-technical issues in the Yubikey's two-factor authentication device.
引用
收藏
页码:222 / 251
页数:30
相关论文
共 50 条
  • [41] Modelling and Analysis of Socio-Technical System of Systems
    Lock, Russell
    Sommerville, Ian
    2010 15TH IEEE INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS (ICECCS 2010), 2010, : 224 - 232
  • [42] Erratum to: Developing immunity to flight security risk: prospective benefits from considering aviation security as a socio-technical eco-system
    Paul McFarlane
    Mils Hills
    Journal of Transportation Security, 2013, 6 (3) : 287 - 287
  • [43] Review of knowledge management systems as socio-technical system
    Assegaff, Setiawan
    Hussin, Ab Razak Che
    International Journal of Computer Science Issues, 2012, 9 (5 5-3): : 129 - 134
  • [44] Specifying and Reasoning over Socio-Technical Security Requirements with STS-Tool
    Paja, Elda
    Dalpiaz, Fabiano
    Poggianella, Mauro
    Roberti, Pierluigi
    Giorgini, Paolo
    CONCEPTUAL MODELING, ER 2013, 2013, 8217 : 504 - +
  • [45] Analysis of Computer Information Management System Security
    Shi, Xiaoling
    Shi, Xiaoping
    Zhang, Zhitian
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON MATERIAL, MECHANICAL AND MANUFACTURING ENGINEERING, 2015, 27 : 1575 - 1578
  • [46] How to Generate Security Cameras: Towards Defence Generation for Socio-Technical Systems
    Gadyatskaya, Olga
    GRAPHICAL MODELS FOR SECURITY, GRAMSEC 2015, 2016, 9390 : 50 - 65
  • [47] Analysing the Efficacy of Security Policies in Cyber-Physical Socio-Technical Systems
    Lenzini, Gabriele
    Mauw, Sjouke
    Ouchani, Samir
    SECURITY AND TRUST MANAGEMENT, STM 2016, 2016, 9871 : 170 - 178
  • [48] Nanomedicine: a socio-technical system
    Massaro, Sebastiano
    Lorenzoni, Gianni
    TECHNOLOGICAL FORECASTING AND SOCIAL CHANGE, 2021, 173
  • [49] How will renewables expansion and hydrocarbon decline impact security? Analysis from a socio-technical transitions perspective
    Kivimaa, Paula
    Sivonen, Marja Helena
    ENVIRONMENTAL INNOVATION AND SOCIETAL TRANSITIONS, 2023, 48
  • [50] Ethical Decision-Making in e-Learning: A Socio-technical Analysis of Informal Security Controls
    Oakley, Richelle L.
    Singh, Rahul
    AMCIS 2011 PROCEEDINGS, 2011,