The Experts below are selected from a list of 21 Experts worldwide ranked by ideXlab platform
Tobias Ruighaver - One of the best experts on this subject based on the ideXlab platform.
-
SEC - A Top-Down Approach Towards Translating Organizational Security Policy Directives to System Audit Configuration
IFIP Advances in Information and Communication Technology, 2002Co-Authors: Atif Ahmad, Tobias RuighaverAbstract:There is a significant gap between the stated objectives of organizational security found in corporate security policy and the Audit Configuration of event logs present on IT systems. Audit Configuration has always been a bottom-up process. As a result, the design and implementation of Audit Configurations is often constrained by the Audit management interface that often models operating system structures rather than real world behavior. This paper argues for a top-down approach in the establishment of IT Audit policies and practices. We propose that management should develop an organization wide Audit policy that will set mandatory Audit directives and ensures that the Audit Configuration reflects the needs of the organization as defined in the security policy.
-
a top down approach towards translating organizational security policy directives to system Audit Configuration
Information Security, 2002Co-Authors: Atif Ahmad, Tobias RuighaverAbstract:There is a significant gap between the stated objectives of organizational security found in corporate security policy and the Audit Configuration of event logs present on IT systems. Audit Configuration has always been a bottom-up process. As a result, the design and implementation of Audit Configurations is often constrained by the Audit management interface that often models operating system structures rather than real world behavior. This paper argues for a top-down approach in the establishment of IT Audit policies and practices. We propose that management should develop an organization wide Audit policy that will set mandatory Audit directives and ensures that the Audit Configuration reflects the needs of the organization as defined in the security policy.
Atif Ahmad - One of the best experts on this subject based on the ideXlab platform.
-
SEC - A Top-Down Approach Towards Translating Organizational Security Policy Directives to System Audit Configuration
IFIP Advances in Information and Communication Technology, 2002Co-Authors: Atif Ahmad, Tobias RuighaverAbstract:There is a significant gap between the stated objectives of organizational security found in corporate security policy and the Audit Configuration of event logs present on IT systems. Audit Configuration has always been a bottom-up process. As a result, the design and implementation of Audit Configurations is often constrained by the Audit management interface that often models operating system structures rather than real world behavior. This paper argues for a top-down approach in the establishment of IT Audit policies and practices. We propose that management should develop an organization wide Audit policy that will set mandatory Audit directives and ensures that the Audit Configuration reflects the needs of the organization as defined in the security policy.
-
a top down approach towards translating organizational security policy directives to system Audit Configuration
Information Security, 2002Co-Authors: Atif Ahmad, Tobias RuighaverAbstract:There is a significant gap between the stated objectives of organizational security found in corporate security policy and the Audit Configuration of event logs present on IT systems. Audit Configuration has always been a bottom-up process. As a result, the design and implementation of Audit Configurations is often constrained by the Audit management interface that often models operating system structures rather than real world behavior. This paper argues for a top-down approach in the establishment of IT Audit policies and practices. We propose that management should develop an organization wide Audit policy that will set mandatory Audit directives and ensures that the Audit Configuration reflects the needs of the organization as defined in the security policy.
Julio Angulo - One of the best experts on this subject based on the ideXlab platform.
-
A4Cloud - HCI requirements for Transparency and Accountability Tools for Cloud Service Chains
Lecture Notes in Computer Science, 2015Co-Authors: Simone Fischer-hübner, John Sören Pettersson, Julio AnguloAbstract:This paper elaborates HCI (Human-Computer Interaction) requirements for making cloud data protection tools comprehensible and trustworthy. The requirements and corresponding user interface design principles are derived from our research and review work conducted to address in particular the following HCI challenges: How can the users be guided to better comprehend the flow and traces of data on the Internet and in the cloud? How can individual end users be supported to do better informed decisions on how their data can be used by cloud providers or others? How can the legal privacy principle of transparency and accountability be enforced by the user interfaces of cloud inspection tools? How can the user interfaces help users to reassess their trust/distrust in services? The research methods that we have used comprise stakeholder workshops, focus groups, controlled experiments, usability tests as well as literature and law reviews. The derived requirements and principles are grouped into the following functional categories: (1) ex-ante transparency, (2) exercising data subject rights, (3) obtaining consent, (4) privacy preference management, (5) privacy policy management, (6) ex-post transparency, (7) Audit Configuration, (8) access control management, and (9) privacy risk assessment. This broad categorization makes our results accessible and applicable for any developer within the field of usable privacy and transparency-enhancing technologies for cloud service chains.
Kang Cao - One of the best experts on this subject based on the ideXlab platform.
-
The Research and Application of Configuration Management Based on Equipment of PDM
Advanced Materials Research, 2013Co-Authors: Zheng Cheng, Kang CaoAbstract:Along with advance of equipment manufacture engineering item complexity, retrench of development time, increasing of product quantity, and bring huge challenge to Configuration management of traditional paper-based technique. This paper taken engineering project as an example which participated and implementary in, expounded the application of PDM system in four aspects of Configuration management: design Configuration, control Configuration, on-the-spot report Configuration, and Audit Configuration. It was clarified important significance which is PDM system advanced level and efficiency in the Configuration management of equipment product development.
Simone Fischer-hübner - One of the best experts on this subject based on the ideXlab platform.
-
A4Cloud - HCI requirements for Transparency and Accountability Tools for Cloud Service Chains
Lecture Notes in Computer Science, 2015Co-Authors: Simone Fischer-hübner, John Sören Pettersson, Julio AnguloAbstract:This paper elaborates HCI (Human-Computer Interaction) requirements for making cloud data protection tools comprehensible and trustworthy. The requirements and corresponding user interface design principles are derived from our research and review work conducted to address in particular the following HCI challenges: How can the users be guided to better comprehend the flow and traces of data on the Internet and in the cloud? How can individual end users be supported to do better informed decisions on how their data can be used by cloud providers or others? How can the legal privacy principle of transparency and accountability be enforced by the user interfaces of cloud inspection tools? How can the user interfaces help users to reassess their trust/distrust in services? The research methods that we have used comprise stakeholder workshops, focus groups, controlled experiments, usability tests as well as literature and law reviews. The derived requirements and principles are grouped into the following functional categories: (1) ex-ante transparency, (2) exercising data subject rights, (3) obtaining consent, (4) privacy preference management, (5) privacy policy management, (6) ex-post transparency, (7) Audit Configuration, (8) access control management, and (9) privacy risk assessment. This broad categorization makes our results accessible and applicable for any developer within the field of usable privacy and transparency-enhancing technologies for cloud service chains.