Towards Optimal Risk-Aware Security Compliance of a Large IT System

被引:0
|
作者
Coffman, Daniel [1 ]
Agrawal, Bhavna [2 ]
Schaffa, Frank [2 ]
机构
[1] Walker Digital LLC, Stamford, CT 06905 USA
[2] IBM Corp, Thomas J Watson Res Ctr, Box 218, Yorktown Hts, NY 10598 USA
来源
关键词
Risk-aware compliance; cloud computing; compliance metrics; compliance optimization;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
A modern information technology (IT) system may consist of thousands of servers, software components and other devices. Operational security of such a system is usually measured by the compliance of the system with a group of security policies. However, there is no generally accepted method of assessing the risk-aware compliance of an IT system with a given set of security policies. The current practice is to state the fraction of non-compliant systems, regardless of the varying levels of risk associated with violations of the policies and their exposure time windows. We propose a new metric that takes into account the risk of non-compliance, along with the number and duration of violations. This metric affords a risk-aware compliance posture in a single number. It is used to determine a course of remediation, returning the system to an acceptable level of risk while minimizing the cost of remediation and observing the physical constraints on the system, and the limited human labor available. This metric may also be used in the course of the normal operation of the IT system, alerting the operators to potential security breaches in a timely manner.
引用
收藏
页码:639 / 651
页数:13
相关论文
共 50 条
  • [1] Towards autonomic risk-aware security configuration
    Ahmed, Mohammad Salim
    Al-Shaer, Ehab
    Taibah, Mohamed Mahmoud
    Abedin, Muhammad
    Khan, Latifur
    2008 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, VOLS 1 AND 2, 2008, : 722 - +
  • [2] Towards risk-aware communications networking
    Cholda, Piotr
    Folstad, Eirik L.
    Helvik, Bjarne E.
    Kuusela, Pirkko
    Naldi, Maurizio
    Norros, Ilkka
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2013, 109 : 160 - 174
  • [3] Towards Risk-Aware Resource Selection
    Markov, Ilya
    Carman, Mark
    Crestani, Fabio
    INFORMATION RETRIEVAL TECHNOLOGY, AIRS 2014, 2014, 8870 : 148 - 159
  • [4] Towards risk-aware resource selection
    1600, Springer Verlag (8870):
  • [5] Towards Risk-Aware Cost-Optimal Resource Allocation for Cloud Applications
    Chhetri, Mohan Baruwal
    Forkan, Abdur Rahim Mohammad
    Vo, Quoc Bao
    Nepal, Surya
    Kowalczyk, Ryszard
    2019 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (IEEE SCC 2019), 2019, : 210 - 214
  • [6] Risk-aware Distributed Optimal Power Flow in Coordinated Transmission and Distribution System
    Aamir Nawaz
    Hongtao Wang
    Journal of Modern Power Systems and Clean Energy, 2021, 9 (03) : 502 - 515
  • [7] Risk-aware Distributed Optimal Power Flow in Coordinated Transmission and Distribution System
    Nawaz, Aamir
    Wang, Hongtao
    JOURNAL OF MODERN POWER SYSTEMS AND CLEAN ENERGY, 2021, 9 (03) : 502 - 515
  • [8] Towards Risk-aware Scheduling of Enterprise Architecture Roadmaps
    Ponsard, Christophe
    Germeau, Fabian
    Ospina, Gustavo
    PROCEEDINGS OF THE 21ST INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS (ICEIS 2019), VOL 2, 2019, : 696 - 702
  • [9] Towards Risk-Aware Planning of Service Delivery Operations
    Vasa, Mitesh
    Jadatharan, Ashok
    Srivastava, Biplav
    2015 IEEE 12TH INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (SCC 2015), 2015, : 82 - 89
  • [10] PROTRIP: Probabilistic Risk-Aware Optimal Transit Planner
    Thangeda, Pranay
    Ornik, Melkior
    2020 IEEE 23RD INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS (ITSC), 2020,