Towards a holistic Information Security Governance Framework for SOA

被引:8
|
作者
Coetzee, Marijke [1 ]
机构
[1] Univ Johannesburg, Acad Comp Sci & Software Engn, Johannesburg, South Africa
关键词
SOA; governance; ISMS; 27001; 27002; SABSA;
D O I
10.1109/ARES.2012.62
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Service Oriented Architecture (SOA) is a design paradigm that enables applications to be built from business processes to support enterprise architecture. This architecture introduces information security challenges that are not comprehensively addressed by current best-practices. This paper evaluates if an Information Security Management System (ISMS), defined by the international standard ISO/IEC 27001 and 27002 can be used to comprehensively support Information Security governance for SOA. As SOA governance, a separate and distinct governance framework, also addresses information security to a certain extent, managers are faced the difficult task of deciding whether their SOA sufficiently protected by the different frameworks. The conclusion is that information security for SOA needs to be addressed more holistically, following an Enterprise Information Security Architecture (EISA) approach where Enterprise Architecture (EA) is concerned with the design of the overall architectural vision of an organization. The framework chosen for this purpose is SABSA, a well-known enterprise security architecture. Using the example of access control to highlight challenges, it becomes clear that Information Security governance for SOA can benefit from an approach such as SABSA.
引用
收藏
页码:155 / 160
页数:6
相关论文
共 50 条
  • [1] Towards a Framework for Strategic Security Context in Information Security Governance
    Maynard, Sean B.
    Tan, Terrence
    Ahmad, Atif
    Ruighaver, Tobias
    [J]. PACIFIC ASIA JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2018, 10 (04): : 65 - 88
  • [2] Towards the Formulation of Information Security Governance Framework for the Banking System
    Ula, Munirul
    Sidek, Zailani Mohamed
    Ismail, Zuraini Bt
    [J]. BUSINESS TRANSFORMATION THROUGH INNOVATION AND KNOWLEDGE MANAGEMENT: AN ACADEMIC PERSPECTIVE, VOLS 1-2, 2010, : 1261 - 1270
  • [3] An information security governance framework
    Da Veiga, A.
    Eloff, J. H. P.
    [J]. INFORMATION SYSTEMS MANAGEMENT, 2007, 24 (04) : 361 - 372
  • [4] A framework for the governance of information security
    Posthumus, S
    von Solms, R
    [J]. COMPUTERS & SECURITY, 2004, 23 (08) : 638 - 646
  • [5] Towards a holistic information security Framework for South African Small and Medium Enterprises
    Dube, Erick
    Flowerday, Stephen
    [J]. 2018 1ST INTERNATIONAL CONFERENCE ON COMPUTER APPLICATIONS & INFORMATION SECURITY (ICCAIS' 2018), 2018,
  • [6] A Framework for Information Security Governance and Management
    Carcary, Marian
    Renaud, Karen
    McLaughlin, Stephen
    O'Brien, Conor
    [J]. IT PROFESSIONAL, 2016, 18 (02) : 22 - 30
  • [7] Towards an Evaluation Framework for SOA Security Testing Tools
    Kabbani, Nawwar
    Tilley, Scott
    Pearson, Lewis
    [J]. 2010 IEEE INTERNATIONAL SYSTEMS CONFERENCE, 2010, : 438 - 443
  • [8] Towards an Information Governance Framework for the Cloud
    George, Elaine
    Gao, Jing
    [J]. VISION 2020: SUSTAINABLE GROWTH, ECONOMIC DEVELOPMENT, AND GLOBAL COMPETITIVENESS, VOLS 1-5, 2014, : 1993 - 2011
  • [9] Secure Information Assets with Data: An Information Security Governance Framework Using Orchestrated Data Analytics from a Holistic Perspective
    Chen, Huaying
    Song, Zhijun
    [J]. PROCEEDINGS OF THE 2016 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ELECTRONIC TECHNOLOGY, 2016, 48 : 179 - 183
  • [10] Holistic framework for evaluating and improving information security culture
    Arbanas, Krunoslav
    Spremic, Mario
    Zajdela Hrustek, Nikolina
    [J]. ASLIB JOURNAL OF INFORMATION MANAGEMENT, 2021, 73 (05) : 699 - 719