DocumentCode :
1736452
Title :
IT confidentiality risk assessment for an architecture-based approach
Author :
Morali, A. ; Zambon, E. ; Etalle, S. ; Overbeek, P.L.
Author_Institution :
Univ. of Twente, Enschede, Netherlands
fYear :
2008
Firstpage :
31
Lastpage :
40
Abstract :
Information systems require awareness of risks and a good understanding of vulnerabilities and their exploitations. In this paper, we propose a novel approach for the systematic assessment and analysis of confidentiality risks caused by disclosure of operational and functional information. The approach is based on a model integrating information assets and the IT infrastructure that they rely on for distributed systems. IT infrastructures enable one to analyse risk propagation possibilities and calculate the impact of confidentiality incidents. Furthermore, our approach is a mean to bridge the technical and business- oriented views of information systems, since the importance of information assets, which is leading the technical decisions, is set by the business.
Keywords :
Internet; risk analysis; software architecture; systems analysis; IT confidentiality risk assessment; IT infrastructures; architecture-based approach; functional information; Bridges; Computer hacking; Credit cards; Databases; ISO standards; Information analysis; Information security; Risk analysis; Risk management; Solids;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Business-driven IT Management, 2008. BDIM 2008. 3rd IEEE/IFIP International Workshop on
Conference_Location :
Salvador
Print_ISBN :
978-1-4244-2191-6
Type :
conf
DOI :
10.1109/BDIM.2008.4540072
Filename :
4540072
Link To Document :
بازگشت