Towards a holistic Information Security Governance Framework for SOA

被引:8
|
作者
Coetzee, Marijke [1 ]
机构
[1] Univ Johannesburg, Acad Comp Sci & Software Engn, Johannesburg, South Africa
关键词
SOA; governance; ISMS; 27001; 27002; SABSA;
D O I
10.1109/ARES.2012.62
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Service Oriented Architecture (SOA) is a design paradigm that enables applications to be built from business processes to support enterprise architecture. This architecture introduces information security challenges that are not comprehensively addressed by current best-practices. This paper evaluates if an Information Security Management System (ISMS), defined by the international standard ISO/IEC 27001 and 27002 can be used to comprehensively support Information Security governance for SOA. As SOA governance, a separate and distinct governance framework, also addresses information security to a certain extent, managers are faced the difficult task of deciding whether their SOA sufficiently protected by the different frameworks. The conclusion is that information security for SOA needs to be addressed more holistically, following an Enterprise Information Security Architecture (EISA) approach where Enterprise Architecture (EA) is concerned with the design of the overall architectural vision of an organization. The framework chosen for this purpose is SABSA, a well-known enterprise security architecture. Using the example of access control to highlight challenges, it becomes clear that Information Security governance for SOA can benefit from an approach such as SABSA.
引用
收藏
页码:155 / 160
页数:6
相关论文
共 50 条
  • [41] A framework for multi-platform SOA security analyses
    Weber, Sam
    Austel, Paula
    McIntosh, Michael
    [J]. 2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 102 - +
  • [42] Healthcare System Evolution towards SOA: A Security Perspective
    Koufi, Vassiliki
    Malamateniou, Flora
    Vassilacopoulos, George
    Papakonstantinou, Despina
    [J]. MEDINFO 2010, PTS I AND II, 2010, 160 : 874 - 878
  • [43] TACTICS: Validation of the security framework developed for tactical SOA
    Gkioulos, Vasileios
    Risthein, Erko
    Wolthusen, Stephen D.
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2017, 35 : 96 - 105
  • [44] Holistic Approach for Governing Information System Security
    Spremic, Mario
    [J]. WORLD CONGRESS ON ENGINEERING - WCE 2013, VOL II, 2013, : 1242 - 1247
  • [45] Information security risks management framework - A step towards mitigating security risks in university network
    Joshi, Chanchala
    Singh, Umesh Kumar
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2017, 35 : 128 - 137
  • [46] TOWARDS A FRAMEWORK FOR HOLISTIC IDEATION IN CONCEPTUAL DESIGN
    Mohan, Manikandan
    Chen, Ying
    Shah, Jami J.
    [J]. PROCEEDINGS OF THE ASME INTERNATIONAL DESIGN ENGINEERING TECHNICAL CONFERENCES AND COMPUTERS AND INFORMATION IN ENGINEERING CONFERENCE, 2011, VOL 2, PTS A AND B, 2012, : 661 - 672
  • [47] Towards a Holistic Framework for Explainable Robot Navigation
    Halilovic, Amar
    Krivic, Senka
    [J]. HUMAN-FRIENDLY ROBOTICS 2023, HFR 2023, 2024, 29 : 213 - 228
  • [48] Towards a Holistic Framework of Knowledge Worker Productivity
    Oskarsdottir, Helga Guorun
    Oddsson, Guomundur Valur
    Sturluson, Jon Por
    Saemundsson, Rognvaldur Johann
    [J]. ADMINISTRATIVE SCIENCES, 2022, 12 (02)
  • [49] Towards a holistic framework for road safety in Australia
    May, Murray
    Tranter, Paul J.
    Warn, James R.
    [J]. JOURNAL OF TRANSPORT GEOGRAPHY, 2008, 16 (06) : 395 - 405
  • [50] Towards a more holistic framework for economic geography
    Perrons, D
    [J]. ANTIPODE, 2001, 33 (02) : 208 - 215