DocumentCode :
3069252
Title :
The Process of Engineering of Security of Information Systems (ESIS): The Formalism of Business Processes
Author :
Goudalo, Wilson ; Seret, Dominique
Author_Institution :
Res. Center in Inf. of Paris CRIP5, Paris Descartes Univ., Paris, France
fYear :
2009
fDate :
18-23 June 2009
Firstpage :
105
Lastpage :
113
Abstract :
Companies and organizations are faced with quite a tough competition and increasing regulatory and legal constraints. Therefore, the use of security risk management is evolving and becoming more and more important in companies and organizations. We define engineering of security of information systems as a process whose aim is to guarantee the global security of information systems, in their eco-system in order to meet the stakes of companies. After our article focused on the encapsulation of security know-how into UML profiles, we focus this work on the presentation of the process of engineering of security into the formalism of business processes. The main idea is to succeed the adherence, of all stakeholders of the enterprise, into the security problem. To meet these pragmatic and actual needs of companies and organizations, we would suggest an approach to engineering of security, firstly, based on the standards and good practices of security and, secondly, inspired from the best practices and feedback of advances in the engineering of information systems. This paper shows the feasibility of mapping the process of engineering of security of information systems into the formalism of business process, and presents the concepts of engineering of security of information systems using the foundations and models of information systems engineering.
Keywords :
Unified Modeling Language; business data processing; information systems; risk management; security of data; UML profile; business process formalism; engineering-of-security; information system; legal constraint; security risk management; Companies; Encapsulation; Information security; Information systems; Law; Legal factors; Management information systems; Risk management; Systems engineering and theory; Unified modeling language; Business Process Formalism; Engineering Process; Enterprise Architecture; Information Systems Security Engineering; Information Systems Urbanization; UML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Emerging Security Information, Systems and Technologies, 2009. SECURWARE '09. Third International Conference on
Conference_Location :
Athens, Glyfada
Print_ISBN :
978-0-7695-3668-2
Type :
conf
DOI :
10.1109/SECURWARE.2009.24
Filename :
5211029
Link To Document :
بازگشت