Integrating Security Risk Management into Business Process Management for the Cloud

被引:8
|
作者
Goettelmann, Elio [1 ,2 ]
Mayer, Nicolas [2 ]
Godart, Claude [1 ]
机构
[1] Univ Lorraine, LORIA INRIA Grand Est, Nancy, France
[2] CRP Henri Tudor, L-1855 Luxembourg, Luxembourg
关键词
Business Process Management; Security Risk Management; Cloud Computing;
D O I
10.1109/CBI.2014.29
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security issues are still preventing wider adoption of cloud computing, especially for businesses which are handling sensitive information. Indeed, by outsourcing its information system (IS), a company can lose control over its infrastructure, its software or even its data. Therefore, new methods and tools need to be defined to respond to this challenge. In this paper we propose to integrate Security Risk Management approaches into Business Process Management to effectively treat security issues at the early phases of the Information System construction. We focus on cloud brokers, emerging actors of the cloud delivery model, who enhance and aggregate existing cloud services to match them with their cloud consumers' requirements. Our main goal is to provide them with tools and techniques to increase the global security level of an IS through different risk treatment strategies.
引用
收藏
页码:86 / 93
页数:8
相关论文
共 50 条
  • [1] Security in business process management
    Sicherheit in Geschäftsprozessmanagement
    Accorsi, Rafael (raccorsi@acm.org), 2013, De Gruyter Oldenbourg (55):
  • [2] Security in Business Process Management
    Accorsi, Rafael
    IT-INFORMATION TECHNOLOGY, 2013, 55 (06): : 215 - 216
  • [3] A Framework for Cloud Security Risk Management based on the Business Objectives of Organizations
    Youssef, Ahmed E.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (12) : 186 - 194
  • [4] An Extension of Business Process Model and Notation for Security Risk Management
    Altuhhova, Olga
    Matulevicius, Raimundas
    Ahmed, Naved
    INTERNATIONAL JOURNAL OF INFORMATION SYSTEM MODELING AND DESIGN, 2013, 4 (04) : 93 - 113
  • [5] Enabling security risk assessment and management for business process models
    Rosado, David G.
    Sanchez, Luis E.
    Jesus Varela-Vaca, Angel
    Santos-Olmo, Antonio
    Teresa Goemez-Loepez, Maria
    Gasca, Rafael M.
    Fernandez-Medina, Eduardo
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 84
  • [6] Cloud-Based Business Process Security Risk Management: A Systematic Review, Taxonomy, and Future Directions
    Abioye, Temitope Elizabeth
    Arogundade, Oluwasefunmi Tale
    Misra, Sanjay
    Adesemowo, Kayode
    Damasevicius, Robertas
    COMPUTERS, 2021, 10 (12)
  • [7] SECURITY RISK MANAGEMENT - CLOUD ENVIRONMENT
    Zboril, Martin
    STRATEGIC MODELING IN MANAGEMENT, ECONOMY AND SOCIETY (IDIMT-2018), 2018, 47 : 367 - 374
  • [8] Integrating Robotic Process Automation into Business Process Management
    Koenig, Maximilian
    Bein, Leon
    Nikaj, Adriatik
    Weske, Mathias
    BUSINESS PROCESS MANAGEMENT: BLOCKCHAIN AND ROBOTIC PROCESS AUTOMATION FORUM, BPM 2020 BLOCKCHAIN AND RPA FORUM, 2020, 393 : 132 - 146
  • [9] Integrating Sustainability Aspects in Business Process Management
    Larsch, Selim
    Betz, Stefanie
    Duboc, Leticia
    Magdaleno, Andrea Magalhaes
    Bomfim, Camilla
    BUSINESS PROCESS MANAGEMENT WORKSHOPS, BPM 2016, 2017, 281 : 403 - 415
  • [10] A Comparison between Business Process Management and Information Security Management
    Wangen, Gaute
    Snekkenes, Einar Arthur
    FEDERATED CONFERENCE ON COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2014, 2014, 2 : 901 - 910