• DocumentCode
    230551
  • Title

    Identifying risk profiles and mitigating actions for business communication services

  • Author

    Copeland, Rebecca ; Crespi, Noel

  • Author_Institution
    Inst. Mines Telecom, Telecom SudParis, Evry, France
  • fYear
    2014
  • fDate
    17-21 Nov. 2014
  • Firstpage
    236
  • Lastpage
    241
  • Abstract
    Enterprises embracing Bring-Your-Own-Device encounter increased risk to data, applications and network resources. The dilemma is how to address threats with mitigating actions that do not unduly disrupt business, yet protect vulnerable assets. This paper proposes a model that identifies risk context and automatically selects appropriate actions. Risks are detected by conflicting observations, timeline discrepancies and risk-indicating behavior patterns. Detected risks are used to construct risk profiles that capture enterprise´s risk mitigation policies via customizable prioritization, and business attributes are used to determine business profiles. It is proposed to utilize a novel multi-dimensional weighting to highlight relationships of risks with assets/actions. Best-fit profiles for both business and risk are selected via `if-the-shoe-fits´ process. Then, mitigating actions are determined by fusing the risk and business profiles, and precise actions are established via score `tolerance bands´.
  • Keywords
    business communication; risk management; best-fit profiles; bring-your-own-device encounter; business attributes; business communication services; business profiles; customizable prioritization; enterprise risk mitigation policies; if-the-shoe-fits process; multidimensional weighting; risk context; risk detection; risk profiles identification; risk-indicating behavior patterns; score tolerance bands; vulnerable assets; Business; Context; Media; Mobile communication; Monitoring; Quality of service; Security; AHP; BYOD; Fuzzification; MCDM; OLS; OWA; SAW; WPM; context profiling; eignvector;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and Service Management (CNSM), 2014 10th International Conference on
  • Conference_Location
    Rio de Janeiro
  • Type

    conf

  • DOI
    10.1109/CNSM.2014.7014165
  • Filename
    7014165