Overview of Enterprise Information Needs in Information Security Risk Assessment

被引:13
|
作者
Korman, Matus [1 ]
Ekstedt, Mathias [1 ]
Sommestad, Teodor [2 ]
Hallberg, Jonas [2 ]
Bengtsson, Johan [2 ]
机构
[1] KTH, Royal Inst Technol, S-10044 Stockholm, Sweden
[2] FOI, Swedish Def Res Agcy, S-58330 Linkoping, Sweden
关键词
MANAGEMENT;
D O I
10.1109/EDOC.2014.16
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Methods for risk assessment in information security suggest users to collect and consider sets of input information, often notably different, both in type and size. To explore these differences, this study compares twelve established methods on how their input suggestions map to the concepts of ArchiMate, a widely used modeling language for enterprise architecture. Hereby, the study also tests the extent, to which ArchiMate accommodates the information suggested by the methods (e.g., for the use of ArchiMate models as a source of information for risk assessment). Results of this study show how the methods differ in suggesting input information in quantity, as well as in the coverage of the ArchiMate structure. Although the translation between ArchiMate and the methods' input suggestions is not perfect, our results indicate that ArchiMate is capable of modeling fair portions of the information needed for the methods for information security risk assessment, which makes ArchiMate models a promising source of guidance for performing risk assessments.
引用
收藏
页码:42 / 51
页数:10
相关论文
共 50 条
  • [41] On the role of the Facilitator in information security risk assessment
    Lizzie Coles-Kemp
    Richard E. Overill
    Journal in Computer Virology, 2007, 3 (2): : 143 - 148
  • [42] SECURITY TESTS AND SUGGESTIONS FOR ENTERPRISE INFORMATION SECURITY
    Vural, Yilmaz
    Sagiroglu, Seref
    JOURNAL OF THE FACULTY OF ENGINEERING AND ARCHITECTURE OF GAZI UNIVERSITY, 2011, 26 (01): : 89 - 104
  • [43] INFORMATION NEEDS OF SECURITY ANALYSTS
    CHANDRA, G
    JOURNAL OF ACCOUNTANCY, 1975, 140 (06): : 65 - 70
  • [44] INFORMATION NEEDS OF STANDARDS BUREAU AT AN ENTERPRISE
    RIGA, VT
    NAUCHNO-TEKHNICHESKAYA INFORMATSIYA SERIYA 1-ORGANIZATSIYA I METODIKA INFORMATSIONNOI RABOTY, 1973, (04): : 24 - 24
  • [45] IDENTIFYING INFORMATION NEEDS OF BLACK ENTERPRISE
    SULKIN, HA
    MCKERSIE, RB
    ATLANTA ECONOMIC REVIEW, 1974, 24 (02): : 28 - 33
  • [46] Overview of security of information system
    Sekimoto, Mitsugu
    Sakurai, Keita
    Kyokai Joho Imeji Zasshi/Journal of the Institute of Image Information and Television Engineers, 2002, 56 (07):
  • [47] An Overview of Information Security Governance
    Asgarkhani, Mehdi
    Correia, Eduardo
    Sarkar, Amit
    2017 INTERNATIONAL CONFERENCE ON ALGORITHMS, METHODOLOGY, MODELS AND APPLICATIONS IN EMERGING TECHNOLOGIES (ICAMMAET), 2017,
  • [48] NEEDS ASSESSMENT INFORMATION
    RABSATT, S
    PHI DELTA KAPPAN, 1978, 59 (07) : 509 - 509
  • [49] MAJOR FACTORS OF ENTERPRISE INFORMATION SECURITY
    Zhyvko, M. O.
    Bosak, H. Z.
    ACTUAL PROBLEMS OF ECONOMICS, 2009, (98): : 67 - 74
  • [50] A REVIEW ON ENTERPRISE INFORMATION SECURITY AND STANDARDS
    Vural, Yilmaz
    Sagiroglu, Seref
    JOURNAL OF THE FACULTY OF ENGINEERING AND ARCHITECTURE OF GAZI UNIVERSITY, 2008, 23 (02): : 507 - 522