The Experts below are selected from a list of 137187 Experts worldwide ranked by ideXlab platform
Nicolas Mayer - One of the best experts on this subject based on the ideXlab platform.
-
an integrated conceptual model for Information System Security risk management supported by enterprise architecture management
Software and Systems Modeling, 2019Co-Authors: Nicolas Mayer, Eric Grandry, Christophe Feltus, Jocelyn Aubert, Elio Goettelmann, Roel WieringaAbstract:Risk management is today a major steering tool for any organisation wanting to deal with Information System (IS) Security. However, IS Security risk management (ISSRM) remains a difficult process to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with enterprise architecture management (EAM) contributes to deal with these issues. A first step towards a better integration of both domains is to define an integrated EAM-ISSRM conceptual model. This paper is about the elaboration and validation of this model. To do so, we improve an existing ISSRM domain model, i.e. a conceptual model depicting the domain of ISSRM, with the concepts of EAM. The validation of the EAM-ISSRM integrated model is then performed with the help of a validation group assessing the utility and usability of the model.
-
An integrated conceptual model for Information System Security risk management supported by enterprise architecture management
Software & Systems Modeling, 2019Co-Authors: Nicolas Mayer, Eric Grandry, Christophe Feltus, Jocelyn Aubert, Elio Goettelmann, Roel WieringaAbstract:Risk management is today a major steering tool for any organisation wanting to deal with Information System (IS) Security. However, IS Security risk management (ISSRM) remains a difficult process to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with enterprise architecture management (EAM) contributes to deal with these issues. A first step towards a better integration of both domains is to define an integrated EAM-ISSRM conceptual model. This paper is about the elaboration and validation of this model. To do so, we improve an existing ISSRM domain model, i.e. a conceptual model depicting the domain of ISSRM, with the concepts of EAM. The validation of the EAM-ISSRM integrated model is then performed with the help of a validation group assessing the utility and usability of the model.
-
an integrated conceptual model for Information System Security risk management and enterprise architecture management based on togaf archimate iaf and dodaf
arXiv: Cryptography and Security, 2017Co-Authors: Nicolas Mayer, Eric Grandry, Christophe Feltus, Jocelyn Aubert, Elio GoettelmannAbstract:Risk management is today a major steering tool for any organization wanting to deal with Information System (IS) Security. However, IS Security Risk Management (ISSRM) remains difficult to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with Enterprise Architecture Management (EAM) contributes to deal with these issues. A first step towards a better integration of both domains is to define an integrated EAM-ISSRM conceptual model. Among the steps of the research method followed to define such an integrated EAM-ISSRM conceptual, this technical report presents the whole outputs (through alignment tables) of the conceptual alignment between concepts used to model EA (based on ArchiMate, TOGAF, IAF and DoDAF) and concepts of the ISSRM domain model.
-
an integrated conceptual model for Information System Security risk management and enterprise architecture management based on togaf
The Practice of Enterprise Modeling, 2016Co-Authors: Nicolas Mayer, Eric Grandry, Jocelyn Aubert, Christophe FeltusAbstract:Risk management is today a major steering tool for any organization wanting to deal with Information System (IS) Security. However, IS Security Risk Management (ISSRM) remains difficult to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with Enterprise Architecture Management (EAM) contributes to deal with these issues. According to our research agenda, a first step towards a better integration of both domains is to define an EAM-ISSRM conceptual integrated model. To build such a model, we will improve the ISSRM domain model, a conceptual model depicting the domain of ISSRM, with the concepts of EAM. The contribution of this paper is focused on the improvement of the ISSRM domain model with the concepts of TOGAF, a well-known EAM standard.
-
Intentional Perspectives on Information Systems Engineering - A Systematic Approach to Define the Domain of Information System Security Risk Management
Intentional Perspectives on Information Systems Engineering, 2010Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas MatulevičiusAbstract:Today, Security concerns are at the heart of Information Systems, both at technological and organizational levels. With over 200 practitioner-oriented risk management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security risk management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of Information System Security risk management. The proposed domain model can then be used to compare, select or otherwise improve Security risk management methods.
Li Jianhua - One of the best experts on this subject based on the ideXlab platform.
-
Method on network Information System Security assessment based on rough set 1
2008Co-Authors: Wang Qiangmin, Lin Mengquan, Li JianhuaAbstract:Based on the analyzing the concept of network Information System Security assessment, this paper proposed an Information System Security basic attribute model for Information System Security assessment based on optimal Security tree criteria. Then a novel heuristic rough set attributes reduction algorithm was proposed to reduce the attributes and build weight set. The validity and practical value of it were illustrated by an example. The main idea of the Security assessment is improve the assessment efficiency and reduce the cost.
-
SITIS - Method on Network Information System Security Assessment Based on Rough Set
2007 Third International IEEE Conference on Signal-Image Technologies and Internet-Based System, 2007Co-Authors: Wang Qiangmin, Lin Mengquan, Li JianhuaAbstract:Based on the analyzing the concept of network Information System Security assessment, this paper proposed an Information System Security basic attribute model for Information System Security assessment based on optimal Security tree criteria. Then a novel heuristic rough set attributes reduction algorithm was proposed to reduce the attributes and build weight set. The validity and practical value of it were illustrated by an example. The main idea of the Security assessment is improve the assessment efficiency and reduce the cost.
Raimundas Matulevičius - One of the best experts on this subject based on the ideXlab platform.
-
Intentional Perspectives on Information Systems Engineering - A Systematic Approach to Define the Domain of Information System Security Risk Management
Intentional Perspectives on Information Systems Engineering, 2010Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas MatulevičiusAbstract:Today, Security concerns are at the heart of Information Systems, both at technological and organizational levels. With over 200 practitioner-oriented risk management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security risk management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of Information System Security risk management. The proposed domain model can then be used to compare, select or otherwise improve Security risk management methods.
-
a Systematic approach to define the domain of Information System Security risk management
Intentional Perspectives on Information Systems Engineering, 2010Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas MatulevičiusAbstract:Today, Security concerns are at the heart of Information Systems, both at technological and organizational levels. With over 200 practitioner-oriented risk management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security risk management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of Information System Security risk management. The proposed domain model can then be used to compare, select or otherwise improve Security risk management methods.
-
design of a modelling language for Information System Security risk management
Research Challenges in Information Science, 2007Co-Authors: Nicolas Mayer, Patrick Heymans, Raimundas MatulevičiusAbstract:Nowadays, Security has become one of the most demanded characteristics of Information Systems. However, the ways to address Information Systems Security still lack consensus and integration. On the one hand, researchers have extended various modelling languages and methods with Security-oriented constructs in order to take Security concerns into account throughout the development lifecycle. On the other hand, practitioners have developed risk management methods to help estimate the relative importance of Security risks and the costeffectiveness of solutions to tackle them. They are mainly driven by Security standards that help practitioners assess and improve the Security level of their organisations. Obviously, those two families of approaches should be unified so as to maximise the return on investment of implementing Security requirements, and thereby align business and Information technology concerns related to Security. This is the challenge that our research aims to address. This paper presents a research agenda and describes the first steps that were undertaken to achieve it: an alignment of the terminology in the risk management literature and the elaboration of a conceptual model of the risk management domain. Those results will then be inputs for the next phases, which aim to integrate Security and risk management concepts in Information System development methods.
Eric Dubois - One of the best experts on this subject based on the ideXlab platform.
-
EDOC Workshops - Conceptual Integration of Enterprise Architecture Management and Security Risk Management
2013 17th IEEE International Enterprise Distributed Object Computing Conference Workshops, 2013Co-Authors: Eric Grandry, Christophe Feltus, Eric DuboisAbstract:Enterprise Architecture Management (EAM) is considered to provide the mechanism for, amongst others, governing enterprise transformations required by changes in the environment. In this paper, we focus on changes that result from the analysis of Information Security risks and of their impacts on the services delivered by an enterprise. We present how the concepts of an Information System Security risks management domain can be mapped into the ArchiMate enterprise architecture modeling language. We illustrate the application of the proposed approach through the handling of a lab case.
-
Conceptual Integration of Enterprise Architecture Management and Security Risk Management
2013 17th IEEE International Enterprise Distributed Object Computing Conference Workshops, 2013Co-Authors: Eric Grandry, Christophe Feltus, Eric DuboisAbstract:Enterprise Architecture Management (EAM) is considered to provide the mechanism for, amongst others, governing enterprise transformations required by changes in the environment. In this paper, we focus on changes that result from the analysis of Information Security risks and of their impacts on the services delivered by an enterprise. We present how the concepts of an Information System Security risks management domain can be mapped into the ArchiMate enterprise architecture modeling language. We illustrate the application of the proposed approach through the handling of a lab case.
-
Intentional Perspectives on Information Systems Engineering - A Systematic Approach to Define the Domain of Information System Security Risk Management
Intentional Perspectives on Information Systems Engineering, 2010Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas MatulevičiusAbstract:Today, Security concerns are at the heart of Information Systems, both at technological and organizational levels. With over 200 practitioner-oriented risk management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security risk management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of Information System Security risk management. The proposed domain model can then be used to compare, select or otherwise improve Security risk management methods.
-
a Systematic approach to define the domain of Information System Security risk management
Intentional Perspectives on Information Systems Engineering, 2010Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas MatulevičiusAbstract:Today, Security concerns are at the heart of Information Systems, both at technological and organizational levels. With over 200 practitioner-oriented risk management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security risk management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of Information System Security risk management. The proposed domain model can then be used to compare, select or otherwise improve Security risk management methods.
Taimyoung Chung - One of the best experts on this subject based on the ideXlab platform.
-
risk assessment method based on business process oriented asset evaluation for Information System Security
International Conference on Conceptual Structures, 2007Co-Authors: Seonho Park, Taimyoung ChungAbstract:We presented risk assessment methodology focused on business-process oriented asset evaluation and qualitative risk analysis method. The business process-oriented asset evaluation is to evaluate asset's value by the degree of asset contribution related to business process. Namely, asset's value is different according to the importance of department to which asset belongs, the contribution of asset's business, and Security safeguard, etc. We proposed new asset's value evaluation applied to the weight of above factors. The weight is decided by evaluation matrix by Delphi team. We assess risk by qualitative method applied to the improved international standard method which is added the effectiveness of operating safeguard at Information System. It reflects an assumption that they can reduce risk level when existent safeguards are established appropriately. Our model derives to practical risk assessment method than existent risk assessment method, and improves reliability of risk analysis.
-
International Conference on Computational Science (3) - Risk Assessment Method Based on Business Process-Oriented Asset Evaluation for Information System Security
Computational Science – ICCS 2007, 2007Co-Authors: Seonho Park, Taimyoung ChungAbstract:We presented risk assessment methodology focused on business-process oriented asset evaluation and qualitative risk analysis method. The business process-oriented asset evaluation is to evaluate asset's value by the degree of asset contribution related to business process. Namely, asset's value is different according to the importance of department to which asset belongs, the contribution of asset's business, and Security safeguard, etc. We proposed new asset's value evaluation applied to the weight of above factors. The weight is decided by evaluation matrix by Delphi team. We assess risk by qualitative method applied to the improved international standard method which is added the effectiveness of operating safeguard at Information System. It reflects an assumption that they can reduce risk level when existent safeguards are established appropriately. Our model derives to practical risk assessment method than existent risk assessment method, and improves reliability of risk analysis.