Towards a holistic Information Security Governance Framework for SOA

被引:8
|
作者
Coetzee, Marijke [1 ]
机构
[1] Univ Johannesburg, Acad Comp Sci & Software Engn, Johannesburg, South Africa
关键词
SOA; governance; ISMS; 27001; 27002; SABSA;
D O I
10.1109/ARES.2012.62
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Service Oriented Architecture (SOA) is a design paradigm that enables applications to be built from business processes to support enterprise architecture. This architecture introduces information security challenges that are not comprehensively addressed by current best-practices. This paper evaluates if an Information Security Management System (ISMS), defined by the international standard ISO/IEC 27001 and 27002 can be used to comprehensively support Information Security governance for SOA. As SOA governance, a separate and distinct governance framework, also addresses information security to a certain extent, managers are faced the difficult task of deciding whether their SOA sufficiently protected by the different frameworks. The conclusion is that information security for SOA needs to be addressed more holistically, following an Enterprise Information Security Architecture (EISA) approach where Enterprise Architecture (EA) is concerned with the design of the overall architectural vision of an organization. The framework chosen for this purpose is SABSA, a well-known enterprise security architecture. Using the example of access control to highlight challenges, it becomes clear that Information Security governance for SOA can benefit from an approach such as SABSA.
引用
收藏
页码:155 / 160
页数:6
相关论文
共 50 条
  • [21] What do we know about information security governance? "From the basement to the boardroom": towards digital security governance
    Schinagl, Stef
    Shahim, Abbas
    [J]. INFORMATION AND COMPUTER SECURITY, 2020, 28 (02) : 261 - 292
  • [22] TOWARDS A FRAMEWORK FOR THE INTEGRATION OF INFORMATION SECURITY INTO UNDERGRADUATE COMPUTING CURRICULA
    Thomson, K-L
    Futcher, L. A.
    Gomana, L.
    [J]. SOUTH AFRICAN JOURNAL OF HIGHER EDUCATION, 2019, 33 (03) : 155 - 175
  • [23] Information systems security and the information systems development project Towards a framework for their integration
    Tryfonas, T
    Kiountouzis, E
    [J]. SECURITY IN THE INFORMATION SOCIETY: VISIONS AND PERSPECTIVES, 2002, 86 : 347 - 356
  • [24] Applying information security governance
    Moulton, R
    Coles, RS
    [J]. COMPUTERS & SECURITY, 2003, 22 (07) : 580 - 584
  • [25] Towards a Data-Driven Enterprise: Effects on Information, Governance, Infrastructures and Security
    Polzonetti, A.
    Sagratella, M.
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT (IEEM), 2017, : 1480 - 1484
  • [26] Corporate governance and information security
    von Solms, B
    [J]. COMPUTERS & SECURITY, 2001, 20 (03) : 215 - 218
  • [27] IT-Governance Framework Considering Service Quality and Information Security in Banks in India
    Singh, Ranjit
    Pandiya, Bhartrihari
    Upadhyay, Chandra Kant
    Singh, Manas K.
    [J]. INTERNATIONAL JOURNAL OF HUMAN CAPITAL AND INFORMATION TECHNOLOGY PROFESSIONALS, 2020, 11 (01) : 64 - 91
  • [28] An Overview of Information Security Governance
    Asgarkhani, Mehdi
    Correia, Eduardo
    Sarkar, Amit
    [J]. 2017 INTERNATIONAL CONFERENCE ON ALGORITHMS, METHODOLOGY, MODELS AND APPLICATIONS IN EMERGING TECHNOLOGIES (ICAMMAET), 2017,
  • [29] Improved Security through Information Security Governance
    Johnston, Allen C.
    Hale, Ron
    [J]. COMMUNICATIONS OF THE ACM, 2009, 52 (01) : 126 - 129
  • [30] A holistic framework for process safety and security analysis
    Amin, Md. Tanjin
    Khan, Faisal
    Halim, Syeda Z.
    Pistikopoulos, Stratos
    [J]. COMPUTERS & CHEMICAL ENGINEERING, 2022, 165