Towards Optimal Risk-Aware Security Compliance of a Large IT System

被引:0
|
作者
Coffman, Daniel [1 ]
Agrawal, Bhavna [2 ]
Schaffa, Frank [2 ]
机构
[1] Walker Digital LLC, Stamford, CT 06905 USA
[2] IBM Corp, Thomas J Watson Res Ctr, Box 218, Yorktown Hts, NY 10598 USA
来源
关键词
Risk-aware compliance; cloud computing; compliance metrics; compliance optimization;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
A modern information technology (IT) system may consist of thousands of servers, software components and other devices. Operational security of such a system is usually measured by the compliance of the system with a group of security policies. However, there is no generally accepted method of assessing the risk-aware compliance of an IT system with a given set of security policies. The current practice is to state the fraction of non-compliant systems, regardless of the varying levels of risk associated with violations of the policies and their exposure time windows. We propose a new metric that takes into account the risk of non-compliance, along with the number and duration of violations. This metric affords a risk-aware compliance posture in a single number. It is used to determine a course of remediation, returning the system to an acceptable level of risk while minimizing the cost of remediation and observing the physical constraints on the system, and the limited human labor available. This metric may also be used in the course of the normal operation of the IT system, alerting the operators to potential security breaches in a timely manner.
引用
收藏
页码:639 / 651
页数:13
相关论文
共 50 条
  • [21] On Optimal Policies for Risk-Aware Sensor Data Collection by a Mobile Agent
    Prasad, Amritha
    Hudack, Jeffrey
    Sundaram, Shreyas
    IFAC PAPERSONLINE, 2019, 52 (20): : 321 - 326
  • [22] Risk-aware optimal planning for a hybrid wind-solar farm
    Yin, Peng-Yeng
    Cheng, Chun-Ying
    Chen, Hsin-Min
    Wu, Tsai-Hung
    RENEWABLE ENERGY, 2020, 157 : 290 - 302
  • [23] Structural Properties of Optimal Risk-Aware Controllers for Spatially Invariant Systems
    Arbelaiz, Juncal
    Bamieh, Bassam
    Leonard, Naomi Ehrich
    IEEE CONTROL SYSTEMS LETTERS, 2023, 7 : 3139 - 3144
  • [24] A Formal Approach Towards Risk-Aware Service Level Analysis and Planning
    Jakoubi, Stefan
    Tjoa, Simon
    Goluch, Sigrun
    Kitzler, Gerhard
    FIFTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY: ARES 2010, PROCEEDINGS, 2010, : 180 - 187
  • [25] Autonomous Risk-Aware Exploration
    Maurer, Johannes
    Steinbauer, Gerald
    2013 IEEE INTERNATIONAL SYMPOSIUM ON SAFETY, SECURITY, AND RESCUE ROBOTICS (SSRR), 2013,
  • [26] Modeling adaptive locomotion behaviors using risk-aware optimal control
    Hubicki, Christian
    Hackett, Jacob
    McGowan, Craig
    Daley, Monica
    INTEGRATIVE AND COMPARATIVE BIOLOGY, 2023, 63 : S207 - S208
  • [27] Towards Risk-aware Access Control Framework for Healthcare Information Sharing
    Abomhara, Mohamed
    Koien, Geir M.
    Oleshchuk, Vladimir A.
    Hamid, Mohamed
    ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 312 - 321
  • [28] Risk-Aware Autonomous Navigation
    Tan, Yew Teck
    Virani, Nurali
    Good, Brandon
    Gray, Steven
    Yousefhussien, Mohammed
    Yang, Zhaoyuan
    Angeliu, Katelyn
    Abate, Nicholas
    Sen, Shiraj
    ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS III, 2021, 11746
  • [29] Risk-Aware Information Disclosure
    Armando, Alessandro
    Bezzi, Michele
    Metoui, Nadia
    Sabetta, Antonino
    DATA PRIVACY MANAGEMENT, AUTONOMOUS SPONTANEOUS SECURITY, AND SECURITY ASSURANCE, 2015, 8872 : 266 - 276
  • [30] Towards Risk-Aware Real-Time Security Constrained Economic Dispatch: A Tailored Deep Reinforcement Learning Approach
    Hu, Jianxiong
    Ye, Yujian
    Tang, Yi
    Strbac, Goran
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2024, 39 (02) : 3972 - 3986