• DocumentCode
    2873894
  • Title

    Integration of an Ontological Information Security Concept in Risk Aware  Business Process Management

  • Author

    Goluch, Gernot ; Ekelhart, Andreas ; Fenz, Stefan ; Jakoubi, Stefan ; Tjoa, Simon ; Mück, Thomas

  • Author_Institution
    Secure Bus. Austria, Vienna
  • fYear
    2008
  • fDate
    7-10 Jan. 2008
  • Firstpage
    377
  • Lastpage
    377
  • Abstract
    The ability to prevent risks as well as to appropriately counteract occurring threats has increasingly become a crucial success factor. Traditional business process management provides concepts for the economical optimization of processes, while risk management focuses on the design of robust business processes. While aiming at the same goal, namely the improvement of business, the approaches how to reach this vary, due to a different understanding of improvement Following this, optimizing recommendations of business process management and risk management may be contradictory. Therefore, we proposed a unified method, integrating both points of views to enable risk-aware business process management and optimization. In this paper, we briefly describe the ROPE (risk-oriented process evaluation) methodology and the security ontology concept, which provides a solid knowledge base for an applicable and holistic company specific IT security approach. This heavy-weight ontology provides structured knowledge regarding the relations between threats, safeguards, and assets, which are crucial for modeling processes in ROPE. We show how the integration of the security ontology´s knowledge base enhances the applicability of the ROPE methodology leading to improved risk-aware business process management.
  • Keywords
    business data processing; ontologies (artificial intelligence); risk management; security of data; economical optimization; ontological information security; risk-aware business process management; risk-oriented process evaluation; Business continuity; Companies; Design optimization; Information security; Monitoring; Ontologies; Optimization methods; Resilience; Risk management; Robustness;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Hawaii International Conference on System Sciences, Proceedings of the 41st Annual
  • Conference_Location
    Waikoloa, HI
  • ISSN
    1530-1605
  • Type

    conf

  • DOI
    10.1109/HICSS.2008.211
  • Filename
    4439082