The Experts below are selected from a list of 60 Experts worldwide ranked by ideXlab platform
Ying He - One of the best experts on this subject based on the ideXlab platform.
-
Generic Security Templates for information system Security arguments: mapping Security arguments within healthcare systems
2020Co-Authors: Ying HeAbstract:Industry reports indicate that the number of Security incidents happened in healthcare organisation is increasing. Lessons learned (i.e. the causes of a Security incident and the recommendations intended to avoid any recurrence) from those Security incidents should ideally inform information Security management systems (ISMS). The sharing of the lessons learned is an essential activity in the “follow-up” phase of Security incident response lifecycle, which has long been addressed but not given enough attention in academic and industry. This dissertation proposes a novel approach, the Generic Security Template (GST), aiming to feed back the lessons learned from real world Security incidents to the ISMS. It adapts graphical Goal Structuring Notations (GSN), to present the lessons learned in a structured manner through mapping them to the Security requirements of the ISMS. The suitability of the GST has been confirmed by demonstrating that instances of the GST can be produced from real world Security incidents of different countries based on in-depth analysis of case studies. The usability of the GST has been evaluated using a series of empirical studies. The GST is empirically evaluated in terms of its given effectiveness in assisting the communication of the lessons learned from Security incidents as compared to the traditional text based approach alone. The results show that the GST can help to improve the accuracy and reduce the mental efforts in assisting the identification of the lessons learned from Security incidents and the results are statistically significant. The GST is further evaluated to determine whether users can apply the GST to structure insights derived from a specific Security incident. The results show that students with a computer science background can create an instance of the GST. The acceptability of the GST is assessed in a healthcare organisation. Strengths and weaknesses are identified and the GST has been adjusted to fit into organisational needs. The GST is then further tested to examine its capability to feed back the Security lessons to the ISMS. The results show that, by using the GST, lessons identified from Security incidents from one healthcare organisation in a specific country can be transferred to another and can indeed inform the improvements of the ISMS. In summary, the GST provides a unified way to feed back the lessons learned to the ISMS. It fosters an environment where different stakeholders can speak the same language while exchanging the lessons learned from the Security incidents around the world.
-
Security Assurance Modelling of Security Incident in Healthcare using the Generic Security Template (GST)
2020Co-Authors: Ying HeAbstract:Abstract Background: The recent industry reports show that the number of Security incidents in healthcare sector is still increasing, especially the high severity incident, such as data leakage incident and ransomware, which can lead to significant impact on healthcare services. It is imperative for the organizations to learn lessons from those incidents. Traditional ways to disseminate lessons learned are based on text approach, the linear format of which can obscure relationships among concepts and discourage readers from integrating information across ideas. Graphical diagrams can serve this purpose, as it can communicate both individual elements of information and relationships between them. Methods: The Generic Security Template (GST) has been proposed to support the exchange of lessons learned from Security incidents. It utilises graphical notations to communicate both individual elements of information and relationships between them. This paper conducts a case study by adopting the GST to capture and structure the incident information of a data leakage incident in a UK healthcare organization in order to facilitate incident exchange. Results: The results show that, the GST was able to visualise and depict the key elements, including lessons learned, the associated Security requirements and organizational contextual information identified from the selected data leakage incident case study from NHS. GST provides a unified way to communicate incident information. Conclusions: This research has significance for the healthcare organizations to improve their incident learning practices. It fosters an environment where different stakeholders can speak the same language while exchanging the lessons learned from the Security incidents. Future work will consider apply the GST to analyse other complex Security incidents such as the advanced persistent threats (APTs) in healthcare organizations and extend the use of the GST in other industries. Keywords: Security Assurance Modelling, Generic Security Template (GST), Security Incident, Healthcare Organization.
-
Improving the exchange of lessons learned in Security incident reports: case studies in the privacy of electronic patient records
Journal of Trust Management, 2015Co-Authors: Ying He, Chris Johnson, Yu LuAbstract:The increasing use of Electronic Health Records has been mirrored by a similar rise in the number of Security incidents where confidential information has inadvertently been disclosed to third parties. These problems have been compounded by an apparent inability to learn from previous violations; similar Security incidents have been observed across Europe, North America and Asia. This has resulted in the loss of confidence and trust of the public towards the organisations’ ability to protect the patients’ private information. The Generic Security Template (G.S.T.) has been proposed to communicate Security lessons learned from previous Security incidents. This paper conducts a series of empirical studies to evaluate the usability of the G.S.T. The first study compares the G.S.T. with the conventional text-based Security incident reports. The two methods were compared in term of the users’ ability to identify a number of lessons learned from investigations into previous incidents involving the disclosure of healthcare records. The study showed that the graphical approach resulted in higher accuracy in terms of number of correct answers generated by participants. However, subjective feedback raised further questions about the usability of the G.S.T. as the readers of Security incident reports try to interpret the lessons that can increase the Security of patient data. The second study further evaluates the usability of the G.S.T. using the Cognitive Dimensions and identifies some aspects that need to be improved.
-
Improving the redistribution of the Security lessons in healthcare: An evaluation of the Generic Security Template
International Journal of Medical Informatics, 2015Co-Authors: Ying He, Chris JohnsonAbstract:Context: The recurrence of past Security breaches in healthcare showed that lessons had not been effectively learned across different healthcare organisations. Recent studies have identified the need to improve learning from incidents and to share Security knowledge to prevent future attacks. Generic Security Templates (GSTs) have been proposed to facilitate this knowledge transfer. The objective of this paper is to evaluate whether potential users in healthcare organisations can exploit the GST technique to share lessons learned from Security incidents. Methodology: We conducted a series of case studies to evaluate GSTs. In particular, we used a GST for a Security incident in the US Veterans' Affairs Administration to explore whether Security lessons could be applied in a very different Chinese healthcare organisation. Results: The results showed that Chinese Security professional accepted the use of GSTs and that cyber Security lessons could be transferred to a Chinese healthcare organisation using this approach. The users also identified the weaknesses and strengths of GSTs, providing suggestions for future improvements. Conclusion: Generic Security Templates can be used to redistribute lessons learned from Security incidents. Sharing cyber Security lessons helps organisations consider their own practices and assess whether applicable Security standards address concerns raised in previous breaches in other countries. The experience gained from this study provides the basis for future work in conducting similar studies in other healthcare organisations.
-
TRUST - Diagraming Approach to Structure the Security Lessons: Evaluation Using Cognitive Dimensions
Trust and Trustworthy Computing, 2014Co-Authors: Ying He, Chris W. Johnson, Maria EvangelopoulouAbstract:Currently, the lessons learned from the Security incidents are documented in add-hoc means such as lengthy Security reports, free-style textual news letters, emails or informal meetings. This makes it difficult to effectively communicate Security lessons among peers and organisations. The diagraming approach such as the Generic Security Template G.S.T. has been proposed to address this problem. This paper extends the work by evaluating its usability using the Cognitive Dimensions and identifies some aspects that need to be improved.
Chris Johnson - One of the best experts on this subject based on the ideXlab platform.
-
Improving the exchange of lessons learned in Security incident reports: case studies in the privacy of electronic patient records
Journal of Trust Management, 2015Co-Authors: Ying He, Chris Johnson, Yu LuAbstract:The increasing use of Electronic Health Records has been mirrored by a similar rise in the number of Security incidents where confidential information has inadvertently been disclosed to third parties. These problems have been compounded by an apparent inability to learn from previous violations; similar Security incidents have been observed across Europe, North America and Asia. This has resulted in the loss of confidence and trust of the public towards the organisations’ ability to protect the patients’ private information. The Generic Security Template (G.S.T.) has been proposed to communicate Security lessons learned from previous Security incidents. This paper conducts a series of empirical studies to evaluate the usability of the G.S.T. The first study compares the G.S.T. with the conventional text-based Security incident reports. The two methods were compared in term of the users’ ability to identify a number of lessons learned from investigations into previous incidents involving the disclosure of healthcare records. The study showed that the graphical approach resulted in higher accuracy in terms of number of correct answers generated by participants. However, subjective feedback raised further questions about the usability of the G.S.T. as the readers of Security incident reports try to interpret the lessons that can increase the Security of patient data. The second study further evaluates the usability of the G.S.T. using the Cognitive Dimensions and identifies some aspects that need to be improved.
-
Improving the redistribution of the Security lessons in healthcare: An evaluation of the Generic Security Template
International Journal of Medical Informatics, 2015Co-Authors: Ying He, Chris JohnsonAbstract:Context: The recurrence of past Security breaches in healthcare showed that lessons had not been effectively learned across different healthcare organisations. Recent studies have identified the need to improve learning from incidents and to share Security knowledge to prevent future attacks. Generic Security Templates (GSTs) have been proposed to facilitate this knowledge transfer. The objective of this paper is to evaluate whether potential users in healthcare organisations can exploit the GST technique to share lessons learned from Security incidents. Methodology: We conducted a series of case studies to evaluate GSTs. In particular, we used a GST for a Security incident in the US Veterans' Affairs Administration to explore whether Security lessons could be applied in a very different Chinese healthcare organisation. Results: The results showed that Chinese Security professional accepted the use of GSTs and that cyber Security lessons could be transferred to a Chinese healthcare organisation using this approach. The users also identified the weaknesses and strengths of GSTs, providing suggestions for future improvements. Conclusion: Generic Security Templates can be used to redistribute lessons learned from Security incidents. Sharing cyber Security lessons helps organisations consider their own practices and assess whether applicable Security standards address concerns raised in previous breaches in other countries. The experience gained from this study provides the basis for future work in conducting similar studies in other healthcare organisations.
-
Improving the Information Security Management: An Industrial Study in the Privacy of Electronic Patient Records
2014 IEEE 27th International Symposium on Computer-Based Medical Systems, 2014Co-Authors: Ying He, Chris Johnson, Yu LuAbstract:Adverse incidents in the privacy of patients' medical records can result in multiple negative impacts. Effective mechanisms are needed to communicate the lessons from the incidents into the Information Security Management Systems (ISMS) so as to prevent similar incidents. The Generic Security Template (G.S.T.) has been developed to enhance current mechanism and has demonstrated significant benefits in communicating the lessons compared to the more conventional use of text-based incident reports. This paper extends the work to evaluate the G.S.T. in healthcare. A case study with healthcare professionals working in a China healthcare organization shows that, the G.S.T. can enhance the current mechanism in communicating the lessons with the ISMS.
-
An empirical study on the use of the Generic Security Template for structuring the lessons from information Security incidents
2014 6th International Conference on Computer Science and Information Technology (CSIT), 2014Co-Authors: Ying He, Chris Johnson, Karen Renaud, Yu Lu, Salem JebrielAbstract:The number of Security incidents is still increasing. The re-occurrence of past breaches shows that lessons have not been effectively learned across different organisations. This illustrates important weaknesses within information Security management systems (ISMS). The sharing of recommendations between public and private organisations has, arguably, not been given enough attention across academic and industry. Many questions remain, for example, about appropriate levels of detail and abstraction that enable different organisations to learn from incidents that occur in other companies within the same or different industries. The Generic Security Template has been proposed, aiming to provide a unified way to share the lessons learned from real world Security incidents. In particular, it adapts the graphical Goal Structuring Notation (GSN), to present lessons learned in a structured manner by mapping them to the Security requirements of the ISMS. In this paper, we have shown how a Generic Security Template can be used to structure graphical overviews of specific incidents. We have also shown the Template can be instantiated to communicate the findings from an investigation into the US VA data breach. Moreover, this paper has empirically evaluated this approach to the creation of a Generic Security Template; this provides users with an overview of the lessons derived from Security incidents at a level of abstraction that can help to implement recommendations in future contexts that are different from those in which an attack originally took place.
Yu Lu - One of the best experts on this subject based on the ideXlab platform.
-
Improving the exchange of lessons learned in Security incident reports: case studies in the privacy of electronic patient records
Journal of Trust Management, 2015Co-Authors: Ying He, Chris Johnson, Yu LuAbstract:The increasing use of Electronic Health Records has been mirrored by a similar rise in the number of Security incidents where confidential information has inadvertently been disclosed to third parties. These problems have been compounded by an apparent inability to learn from previous violations; similar Security incidents have been observed across Europe, North America and Asia. This has resulted in the loss of confidence and trust of the public towards the organisations’ ability to protect the patients’ private information. The Generic Security Template (G.S.T.) has been proposed to communicate Security lessons learned from previous Security incidents. This paper conducts a series of empirical studies to evaluate the usability of the G.S.T. The first study compares the G.S.T. with the conventional text-based Security incident reports. The two methods were compared in term of the users’ ability to identify a number of lessons learned from investigations into previous incidents involving the disclosure of healthcare records. The study showed that the graphical approach resulted in higher accuracy in terms of number of correct answers generated by participants. However, subjective feedback raised further questions about the usability of the G.S.T. as the readers of Security incident reports try to interpret the lessons that can increase the Security of patient data. The second study further evaluates the usability of the G.S.T. using the Cognitive Dimensions and identifies some aspects that need to be improved.
-
Improving the Information Security Management: An Industrial Study in the Privacy of Electronic Patient Records
2014 IEEE 27th International Symposium on Computer-Based Medical Systems, 2014Co-Authors: Ying He, Chris Johnson, Yu LuAbstract:Adverse incidents in the privacy of patients' medical records can result in multiple negative impacts. Effective mechanisms are needed to communicate the lessons from the incidents into the Information Security Management Systems (ISMS) so as to prevent similar incidents. The Generic Security Template (G.S.T.) has been developed to enhance current mechanism and has demonstrated significant benefits in communicating the lessons compared to the more conventional use of text-based incident reports. This paper extends the work to evaluate the G.S.T. in healthcare. A case study with healthcare professionals working in a China healthcare organization shows that, the G.S.T. can enhance the current mechanism in communicating the lessons with the ISMS.
-
CBMS - Improving the Information Security Management: An Industrial Study in the Privacy of Electronic Patient Records
2014 IEEE 27th International Symposium on Computer-Based Medical Systems, 2014Co-Authors: Ying He, Chris W. Johnson, Yu LuAbstract:Adverse incidents in the privacy of patients' medical records can result in multiple negative impacts. Effective mechanisms are needed to communicate the lessons from the incidents into the Information Security Management Systems (ISMS) so as to prevent similar incidents. The Generic Security Template (G.S.T.) has been developed to enhance current mechanism and has demonstrated significant benefits in communicating the lessons compared to the more conventional use of text-based incident reports. This paper extends the work to evaluate the G.S.T. in healthcare. A case study with healthcare professionals working in a China healthcare organization shows that, the G.S.T. can enhance the current mechanism in communicating the lessons with the ISMS.
-
An empirical study on the use of the Generic Security Template for structuring the lessons from information Security incidents
2014 6th International Conference on Computer Science and Information Technology (CSIT), 2014Co-Authors: Ying He, Chris Johnson, Karen Renaud, Yu Lu, Salem JebrielAbstract:The number of Security incidents is still increasing. The re-occurrence of past breaches shows that lessons have not been effectively learned across different organisations. This illustrates important weaknesses within information Security management systems (ISMS). The sharing of recommendations between public and private organisations has, arguably, not been given enough attention across academic and industry. Many questions remain, for example, about appropriate levels of detail and abstraction that enable different organisations to learn from incidents that occur in other companies within the same or different industries. The Generic Security Template has been proposed, aiming to provide a unified way to share the lessons learned from real world Security incidents. In particular, it adapts the graphical Goal Structuring Notation (GSN), to present lessons learned in a structured manner by mapping them to the Security requirements of the ISMS. In this paper, we have shown how a Generic Security Template can be used to structure graphical overviews of specific incidents. We have also shown the Template can be instantiated to communicate the findings from an investigation into the US VA data breach. Moreover, this paper has empirically evaluated this approach to the creation of a Generic Security Template; this provides users with an overview of the lessons derived from Security incidents at a level of abstraction that can help to implement recommendations in future contexts that are different from those in which an attack originally took place.
-
Security Template for structuring the lessons from information Security incidents
2014Co-Authors: Ying He, Karen Renaud, Yu Lu, Salem JebrielAbstract:The number of Security incidents is still increasing. The re-occurrence of past breaches shows that lessons have not been effectively learned across different organisations. This illustrates important weaknesses within information Security management systems (ISMS). The sharing of recommendations between public and private organisations has, arguably, not been given enough attention across academic and industry. Many questions remain, for example, about appropriate levels of detail and abstraction that enable different organisations to learn from incidents that occur in other companies within the same or different industries. The Generic Security Template has been proposed, aiming to provide a unified way to share the lessons learned from real world Security incidents. In particular, it adapts the graphical Goal Structuring Notation (GSN), to present lessons learned in a structured manner by mapping them to the Security requirements of the ISMS. In this paper, we have shown how a Generic Security Template can be used to structure graphical overviews of specific incidents. We have also shown the Template can be instantiated to communicate the findings from an investigation into the US V A data breach. Moreover, this paper has empirically evaluated this approach to the creation of a Generic Security Template; this provides users with an overview ofthe lessons derived from Security incidents at a level of abstraction that can help to implement recommendations in future contexts that are different from those in which an attack originally took place.
David Gilliam - One of the best experts on this subject based on the ideXlab platform.
-
Managing information Technology Security Risk
Lecture Notes in Computer Science, 2020Co-Authors: David GilliamAbstract:Information Technology (IT) Security Risk Management is a critical task for the organization to protect against the loss of confidentiality, integrity, and availability of IT resources and data. Due to system complexity and sophistication of attacks, it is increasingly difficult to manage IT Security risk. This paper describes a two-pronged approach for managing IT Security risk: 1) an institutional approach, that addresses automating the process of providing and maintaining Security for IT systems and the data they contain; and 2) a project life cycle approach that addresses providing semi-automated means for integrating Security into the project life cycle. It also describes the use of a Security Template with a risk reduction/mitigation tool, the Defect Detection and Prevention (DDP) tool developed at the Jet Propulsion Laboratory (JPL).
-
ISSS - Managing Information Technology Security Risk
Lecture Notes in Computer Science, 2003Co-Authors: David GilliamAbstract:Information Technology (IT) Security Risk Management is a critical task for the organization to protect against the loss of confidentiality, integrity, and availability of IT resources and data. Due to system complexity and sophistication of attacks, it is increasingly difficult to manage IT Security risk. This paper describes a two-pronged approach for managing IT Security risk: 1) an institutional approach, that addresses automating the process of providing and maintaining Security for IT systems and the data they contain; and 2) a project life cycle approach that addresses providing semi-automated means for integrating Security into the project life cycle. It also describes the use of a Security Template with a risk reduction/mitigation tool, the Defect Detection and Prevention (DDP) tool developed at the Jet Propulsion Laboratory (JPL).
Salem Jebriel - One of the best experts on this subject based on the ideXlab platform.
-
An empirical study on the use of the Generic Security Template for structuring the lessons from information Security incidents
2014 6th International Conference on Computer Science and Information Technology (CSIT), 2014Co-Authors: Ying He, Chris Johnson, Karen Renaud, Yu Lu, Salem JebrielAbstract:The number of Security incidents is still increasing. The re-occurrence of past breaches shows that lessons have not been effectively learned across different organisations. This illustrates important weaknesses within information Security management systems (ISMS). The sharing of recommendations between public and private organisations has, arguably, not been given enough attention across academic and industry. Many questions remain, for example, about appropriate levels of detail and abstraction that enable different organisations to learn from incidents that occur in other companies within the same or different industries. The Generic Security Template has been proposed, aiming to provide a unified way to share the lessons learned from real world Security incidents. In particular, it adapts the graphical Goal Structuring Notation (GSN), to present lessons learned in a structured manner by mapping them to the Security requirements of the ISMS. In this paper, we have shown how a Generic Security Template can be used to structure graphical overviews of specific incidents. We have also shown the Template can be instantiated to communicate the findings from an investigation into the US VA data breach. Moreover, this paper has empirically evaluated this approach to the creation of a Generic Security Template; this provides users with an overview of the lessons derived from Security incidents at a level of abstraction that can help to implement recommendations in future contexts that are different from those in which an attack originally took place.
-
Security Template for structuring the lessons from information Security incidents
2014Co-Authors: Ying He, Karen Renaud, Yu Lu, Salem JebrielAbstract:The number of Security incidents is still increasing. The re-occurrence of past breaches shows that lessons have not been effectively learned across different organisations. This illustrates important weaknesses within information Security management systems (ISMS). The sharing of recommendations between public and private organisations has, arguably, not been given enough attention across academic and industry. Many questions remain, for example, about appropriate levels of detail and abstraction that enable different organisations to learn from incidents that occur in other companies within the same or different industries. The Generic Security Template has been proposed, aiming to provide a unified way to share the lessons learned from real world Security incidents. In particular, it adapts the graphical Goal Structuring Notation (GSN), to present lessons learned in a structured manner by mapping them to the Security requirements of the ISMS. In this paper, we have shown how a Generic Security Template can be used to structure graphical overviews of specific incidents. We have also shown the Template can be instantiated to communicate the findings from an investigation into the US V A data breach. Moreover, this paper has empirically evaluated this approach to the creation of a Generic Security Template; this provides users with an overview ofthe lessons derived from Security incidents at a level of abstraction that can help to implement recommendations in future contexts that are different from those in which an attack originally took place.