An integrated conceptual model for information system security risk management supported by enterprise architecture management

被引:0
|
作者
Nicolas Mayer
Jocelyn Aubert
Eric Grandry
Christophe Feltus
Elio Goettelmann
Roel Wieringa
机构
[1] Luxembourg Institute of Science and Technology,
[2] University of Twente,undefined
来源
关键词
Risk management; Security; Enterprise architecture; ArchiMate;
D O I
暂无
中图分类号
学科分类号
摘要
Risk management is today a major steering tool for any organisation wanting to deal with information system (IS) security. However, IS security risk management (ISSRM) remains a difficult process to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with enterprise architecture management (EAM) contributes to deal with these issues. A first step towards a better integration of both domains is to define an integrated EAM-ISSRM conceptual model. This paper is about the elaboration and validation of this model. To do so, we improve an existing ISSRM domain model, i.e. a conceptual model depicting the domain of ISSRM, with the concepts of EAM. The validation of the EAM-ISSRM integrated model is then performed with the help of a validation group assessing the utility and usability of the model.
引用
收藏
页码:2285 / 2312
页数:27
相关论文
共 50 条
  • [31] Information security risk assessment model for risk management
    Wawrzyniak, Dariusz
    [J]. TRUST, PRIVACY, AND SECURITY IN DIGITAL BUSINESS, PROCEEDINGS, 2006, 4083 : 21 - 30
  • [32] A conceptual framework for information security management
    Finne, T
    [J]. COMPUTERS & SECURITY, 1998, 17 (04) : 303 - 307
  • [33] Improvement of Information System Security Risk Management
    Abbass, Wissam
    Baina, Amine
    Bellafkih, Mostafa
    [J]. 2016 4TH IEEE INTERNATIONAL COLLOQUIUM ON INFORMATION SCIENCE AND TECHNOLOGY (CIST), 2016, : 182 - 187
  • [34] An integrated system for information security management with the unified framework
    Yang, Tsung-Han
    Ku, Cheng-Yuan
    Liu, Man-Nung
    [J]. JOURNAL OF RISK RESEARCH, 2016, 19 (01) : 21 - 41
  • [35] Conceptual Model of Defect Monitoring in Quality Management of Enterprise Information Systems
    Isaev, G. N.
    Lobanov, N. N.
    [J]. AUTOMATIC DOCUMENTATION AND MATHEMATICAL LINGUISTICS, 2009, 43 (02) : 108 - 113
  • [36] Development of a Supply Chain Management Security Risk Management Method: A Conceptual Model
    Warren, Matthew
    Leitch, Shona
    [J]. PROCEEDINGS OF THE 9TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2010, : 327 - 333
  • [37] Conceptual model of defect monitoring in quality management of enterprise information systems
    G. N. Isaev
    N. N. Lobanov
    [J]. Automatic Documentation and Mathematical Linguistics, 2009, 43 (2) : 108 - 113
  • [38] Research of Information System Security Risk Management based on Probability Model and Security Entropy
    Du, Jiawei
    Zhou, Ying
    Guo, Ronghua
    Zhang, Xing
    Suo, Guowei
    [J]. INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND APPLICATION ENGINEERING (CSAE), 2017, 190 : 414 - 420
  • [39] Design of Integrated Management Information System for Layer Breeding Enterprise
    Zhang, Qian
    Yu, Feng
    Fu, Rong
    Zhang, Jun-Feng
    [J]. INTERNATIONAL CONFERENCE ON MECHANICS AND CONTROL ENGINEERING (MCE 2015), 2015, : 291 - 294
  • [40] Constructing Enterprise Information Network Security Risk Management Mechanism by Ontology
    Liu, Fong-Hao
    Lee, Wei-Tsong
    [J]. JOURNAL OF APPLIED SCIENCE AND ENGINEERING, 2010, 13 (01): : 79 - 87