The Experts below are selected from a list of 137187 Experts worldwide ranked by ideXlab platform

Nicolas Mayer - One of the best experts on this subject based on the ideXlab platform.

  • an integrated conceptual model for Information System Security risk management supported by enterprise architecture management
    Software and Systems Modeling, 2019
    Co-Authors: Nicolas Mayer, Eric Grandry, Christophe Feltus, Jocelyn Aubert, Elio Goettelmann, Roel Wieringa
    Abstract:

    Risk management is today a major steering tool for any organisation wanting to deal with Information System (IS) Security. However, IS Security risk management (ISSRM) remains a difficult process to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with enterprise architecture management (EAM) contributes to deal with these issues. A first step towards a better integration of both domains is to define an integrated EAM-ISSRM conceptual model. This paper is about the elaboration and validation of this model. To do so, we improve an existing ISSRM domain model, i.e. a conceptual model depicting the domain of ISSRM, with the concepts of EAM. The validation of the EAM-ISSRM integrated model is then performed with the help of a validation group assessing the utility and usability of the model.

  • An integrated conceptual model for Information System Security risk management supported by enterprise architecture management
    Software & Systems Modeling, 2019
    Co-Authors: Nicolas Mayer, Eric Grandry, Christophe Feltus, Jocelyn Aubert, Elio Goettelmann, Roel Wieringa
    Abstract:

    Risk management is today a major steering tool for any organisation wanting to deal with Information System (IS) Security. However, IS Security risk management (ISSRM) remains a difficult process to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with enterprise architecture management (EAM) contributes to deal with these issues. A first step towards a better integration of both domains is to define an integrated EAM-ISSRM conceptual model. This paper is about the elaboration and validation of this model. To do so, we improve an existing ISSRM domain model, i.e. a conceptual model depicting the domain of ISSRM, with the concepts of EAM. The validation of the EAM-ISSRM integrated model is then performed with the help of a validation group assessing the utility and usability of the model.

  • an integrated conceptual model for Information System Security risk management and enterprise architecture management based on togaf archimate iaf and dodaf
    arXiv: Cryptography and Security, 2017
    Co-Authors: Nicolas Mayer, Eric Grandry, Christophe Feltus, Jocelyn Aubert, Elio Goettelmann
    Abstract:

    Risk management is today a major steering tool for any organization wanting to deal with Information System (IS) Security. However, IS Security Risk Management (ISSRM) remains difficult to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with Enterprise Architecture Management (EAM) contributes to deal with these issues. A first step towards a better integration of both domains is to define an integrated EAM-ISSRM conceptual model. Among the steps of the research method followed to define such an integrated EAM-ISSRM conceptual, this technical report presents the whole outputs (through alignment tables) of the conceptual alignment between concepts used to model EA (based on ArchiMate, TOGAF, IAF and DoDAF) and concepts of the ISSRM domain model.

  • an integrated conceptual model for Information System Security risk management and enterprise architecture management based on togaf
    The Practice of Enterprise Modeling, 2016
    Co-Authors: Nicolas Mayer, Eric Grandry, Jocelyn Aubert, Christophe Feltus
    Abstract:

    Risk management is today a major steering tool for any organization wanting to deal with Information System (IS) Security. However, IS Security Risk Management (ISSRM) remains difficult to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with Enterprise Architecture Management (EAM) contributes to deal with these issues. According to our research agenda, a first step towards a better integration of both domains is to define an EAM-ISSRM conceptual integrated model. To build such a model, we will improve the ISSRM domain model, a conceptual model depicting the domain of ISSRM, with the concepts of EAM. The contribution of this paper is focused on the improvement of the ISSRM domain model with the concepts of TOGAF, a well-known EAM standard.

  • Intentional Perspectives on Information Systems Engineering - A Systematic Approach to Define the Domain of Information System Security Risk Management
    Intentional Perspectives on Information Systems Engineering, 2010
    Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas Matulevičius
    Abstract:

    Today, Security concerns are at the heart of Information Systems, both at technological and organizational levels. With over 200 practitioner-oriented risk management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security risk management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of Information System Security risk management. The proposed domain model can then be used to compare, select or otherwise improve Security risk management methods.

Li Jianhua - One of the best experts on this subject based on the ideXlab platform.

  • Method on network Information System Security assessment based on rough set 1
    2008
    Co-Authors: Wang Qiangmin, Lin Mengquan, Li Jianhua
    Abstract:

    Based on the analyzing the concept of network Information System Security assessment, this paper proposed an Information System Security basic attribute model for Information System Security assessment based on optimal Security tree criteria. Then a novel heuristic rough set attributes reduction algorithm was proposed to reduce the attributes and build weight set. The validity and practical value of it were illustrated by an example. The main idea of the Security assessment is improve the assessment efficiency and reduce the cost.

  • SITIS - Method on Network Information System Security Assessment Based on Rough Set
    2007 Third International IEEE Conference on Signal-Image Technologies and Internet-Based System, 2007
    Co-Authors: Wang Qiangmin, Lin Mengquan, Li Jianhua
    Abstract:

    Based on the analyzing the concept of network Information System Security assessment, this paper proposed an Information System Security basic attribute model for Information System Security assessment based on optimal Security tree criteria. Then a novel heuristic rough set attributes reduction algorithm was proposed to reduce the attributes and build weight set. The validity and practical value of it were illustrated by an example. The main idea of the Security assessment is improve the assessment efficiency and reduce the cost.

Raimundas Matulevičius - One of the best experts on this subject based on the ideXlab platform.

  • Intentional Perspectives on Information Systems Engineering - A Systematic Approach to Define the Domain of Information System Security Risk Management
    Intentional Perspectives on Information Systems Engineering, 2010
    Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas Matulevičius
    Abstract:

    Today, Security concerns are at the heart of Information Systems, both at technological and organizational levels. With over 200 practitioner-oriented risk management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security risk management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of Information System Security risk management. The proposed domain model can then be used to compare, select or otherwise improve Security risk management methods.

  • a Systematic approach to define the domain of Information System Security risk management
    Intentional Perspectives on Information Systems Engineering, 2010
    Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas Matulevičius
    Abstract:

    Today, Security concerns are at the heart of Information Systems, both at technological and organizational levels. With over 200 practitioner-oriented risk management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security risk management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of Information System Security risk management. The proposed domain model can then be used to compare, select or otherwise improve Security risk management methods.

  • design of a modelling language for Information System Security risk management
    Research Challenges in Information Science, 2007
    Co-Authors: Nicolas Mayer, Patrick Heymans, Raimundas Matulevičius
    Abstract:

    Nowadays, Security has become one of the most demanded characteristics of Information Systems. However, the ways to address Information Systems Security still lack consensus and integration. On the one hand, researchers have extended various modelling languages and methods with Security-oriented constructs in order to take Security concerns into account throughout the development lifecycle. On the other hand, practitioners have developed risk management methods to help estimate the relative importance of Security risks and the costeffectiveness of solutions to tackle them. They are mainly driven by Security standards that help practitioners assess and improve the Security level of their organisations. Obviously, those two families of approaches should be unified so as to maximise the return on investment of implementing Security requirements, and thereby align business and Information technology concerns related to Security. This is the challenge that our research aims to address. This paper presents a research agenda and describes the first steps that were undertaken to achieve it: an alignment of the terminology in the risk management literature and the elaboration of a conceptual model of the risk management domain. Those results will then be inputs for the next phases, which aim to integrate Security and risk management concepts in Information System development methods.

Eric Dubois - One of the best experts on this subject based on the ideXlab platform.

  • EDOC Workshops - Conceptual Integration of Enterprise Architecture Management and Security Risk Management
    2013 17th IEEE International Enterprise Distributed Object Computing Conference Workshops, 2013
    Co-Authors: Eric Grandry, Christophe Feltus, Eric Dubois
    Abstract:

    Enterprise Architecture Management (EAM) is considered to provide the mechanism for, amongst others, governing enterprise transformations required by changes in the environment. In this paper, we focus on changes that result from the analysis of Information Security risks and of their impacts on the services delivered by an enterprise. We present how the concepts of an Information System Security risks management domain can be mapped into the ArchiMate enterprise architecture modeling language. We illustrate the application of the proposed approach through the handling of a lab case.

  • Conceptual Integration of Enterprise Architecture Management and Security Risk Management
    2013 17th IEEE International Enterprise Distributed Object Computing Conference Workshops, 2013
    Co-Authors: Eric Grandry, Christophe Feltus, Eric Dubois
    Abstract:

    Enterprise Architecture Management (EAM) is considered to provide the mechanism for, amongst others, governing enterprise transformations required by changes in the environment. In this paper, we focus on changes that result from the analysis of Information Security risks and of their impacts on the services delivered by an enterprise. We present how the concepts of an Information System Security risks management domain can be mapped into the ArchiMate enterprise architecture modeling language. We illustrate the application of the proposed approach through the handling of a lab case.

  • Intentional Perspectives on Information Systems Engineering - A Systematic Approach to Define the Domain of Information System Security Risk Management
    Intentional Perspectives on Information Systems Engineering, 2010
    Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas Matulevičius
    Abstract:

    Today, Security concerns are at the heart of Information Systems, both at technological and organizational levels. With over 200 practitioner-oriented risk management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security risk management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of Information System Security risk management. The proposed domain model can then be used to compare, select or otherwise improve Security risk management methods.

  • a Systematic approach to define the domain of Information System Security risk management
    Intentional Perspectives on Information Systems Engineering, 2010
    Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas Matulevičius
    Abstract:

    Today, Security concerns are at the heart of Information Systems, both at technological and organizational levels. With over 200 practitioner-oriented risk management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security risk management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of Information System Security risk management. The proposed domain model can then be used to compare, select or otherwise improve Security risk management methods.

Taimyoung Chung - One of the best experts on this subject based on the ideXlab platform.

  • risk assessment method based on business process oriented asset evaluation for Information System Security
    International Conference on Conceptual Structures, 2007
    Co-Authors: Seonho Park, Taimyoung Chung
    Abstract:

    We presented risk assessment methodology focused on business-process oriented asset evaluation and qualitative risk analysis method. The business process-oriented asset evaluation is to evaluate asset's value by the degree of asset contribution related to business process. Namely, asset's value is different according to the importance of department to which asset belongs, the contribution of asset's business, and Security safeguard, etc. We proposed new asset's value evaluation applied to the weight of above factors. The weight is decided by evaluation matrix by Delphi team. We assess risk by qualitative method applied to the improved international standard method which is added the effectiveness of operating safeguard at Information System. It reflects an assumption that they can reduce risk level when existent safeguards are established appropriately. Our model derives to practical risk assessment method than existent risk assessment method, and improves reliability of risk analysis.

  • International Conference on Computational Science (3) - Risk Assessment Method Based on Business Process-Oriented Asset Evaluation for Information System Security
    Computational Science – ICCS 2007, 2007
    Co-Authors: Seonho Park, Taimyoung Chung
    Abstract:

    We presented risk assessment methodology focused on business-process oriented asset evaluation and qualitative risk analysis method. The business process-oriented asset evaluation is to evaluate asset's value by the degree of asset contribution related to business process. Namely, asset's value is different according to the importance of department to which asset belongs, the contribution of asset's business, and Security safeguard, etc. We proposed new asset's value evaluation applied to the weight of above factors. The weight is decided by evaluation matrix by Delphi team. We assess risk by qualitative method applied to the improved international standard method which is added the effectiveness of operating safeguard at Information System. It reflects an assumption that they can reduce risk level when existent safeguards are established appropriately. Our model derives to practical risk assessment method than existent risk assessment method, and improves reliability of risk analysis.