Integrating Security Risk Management into Business Process Management for the Cloud

被引:8
|
作者
Goettelmann, Elio [1 ,2 ]
Mayer, Nicolas [2 ]
Godart, Claude [1 ]
机构
[1] Univ Lorraine, LORIA INRIA Grand Est, Nancy, France
[2] CRP Henri Tudor, L-1855 Luxembourg, Luxembourg
关键词
Business Process Management; Security Risk Management; Cloud Computing;
D O I
10.1109/CBI.2014.29
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security issues are still preventing wider adoption of cloud computing, especially for businesses which are handling sensitive information. Indeed, by outsourcing its information system (IS), a company can lose control over its infrastructure, its software or even its data. Therefore, new methods and tools need to be defined to respond to this challenge. In this paper we propose to integrate Security Risk Management approaches into Business Process Management to effectively treat security issues at the early phases of the Information System construction. We focus on cloud brokers, emerging actors of the cloud delivery model, who enhance and aggregate existing cloud services to match them with their cloud consumers' requirements. Our main goal is to provide them with tools and techniques to increase the global security level of an IS through different risk treatment strategies.
引用
收藏
页码:86 / 93
页数:8
相关论文
共 50 条
  • [41] Integrating Security Aspects into Business Process Models
    Brucker, Achim D.
    IT-INFORMATION TECHNOLOGY, 2013, 55 (06): : 239 - 245
  • [42] The process of integrating risk management: usefulness, standardisation and adaptation
    Leonhardsen, Mette
    Nilsen, Aud Solveig
    Olsen, Odd Einar
    INTERNATIONAL JOURNAL OF EMERGENCY MANAGEMENT, 2022, 17 (3-4) : 255 - 273
  • [43] Operational risk management with process control and business process modeling
    Cernauskas, Deborah
    Tarantino, Anthony
    JOURNAL OF OPERATIONAL RISK, 2009, 4 (02): : 3 - 17
  • [44] IT Security Risk Management: Perceived IT Security Risks in the Context of Cloud Computing.
    Vinaja, Roberto
    JOURNAL OF GLOBAL INFORMATION TECHNOLOGY MANAGEMENT, 2013, 16 (03) : 82 - 84
  • [45] SECURITY AND RISK MANAGEMENT WHEN USING CLOUD COMPUTING IT SERVICES
    Sepulveda O, Erick
    Salcedo, Octavio J.
    Gomez Vargas, Ernesto
    REDES DE INGENIERIA-ROMPIENDO LAS BARRERAS DEL CONOCIMIENTO, 2010, 1 (02): : 10 - 21
  • [46] CLOUD TECHNOLOGIES IN BUSINESS MANAGEMENT
    Gevko, V
    Vivchar, O.
    Sharko, V
    Radchenko, O.
    Budiaiev, M.
    Tarasenko, O.
    FINANCIAL AND CREDIT ACTIVITY-PROBLEMS OF THEORY AND PRACTICE, 2021, 4 (39): : 294 - 301
  • [47] MANAGEMENT AND BUSINESS MODEL RISK PROFILE IN SECURITY SYSTEMS DEVELOPMENT
    Panevski, Valeri
    COMPTES RENDUS DE L ACADEMIE BULGARE DES SCIENCES, 2024, 77 (04): : 569 - 575
  • [48] Towards a Concept for Integrating IT Innovation Management into Business IT Management
    Drews, Paul
    Morisse, Marcel
    Zimmermann, Karsten
    AMCIS 2013 PROCEEDINGS, 2013,
  • [49] MANAGEMENT OF CHANGES AND BUSINESS PROCESS MANAGEMENT
    Paskova, Martina
    PODNIKANIE A KONKURENCIESCHOPNOST' FIRIEM 2010, 2010, : 326 - 343
  • [50] A Theoretical and Empirical Analysis of Risk Management in Business Process
    Xie Kefan
    Liu Jieming
    Chen Yun
    2007 INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-15, 2007, : 6509 - +