• DocumentCode
    660833
  • Title

    Information Security Risk Management in a World of Services

  • Author

    Lalanne, Vincent ; Munier, Manuel ; Gabillon, Alban

  • Author_Institution
    LIUPPA, Univ. Pau & Pays Adour, Pau, France
  • fYear
    2013
  • fDate
    8-14 Sept. 2013
  • Firstpage
    586
  • Lastpage
    593
  • Abstract
    Service Oriented Architectures (SOA) offer new opportunities for the interconnection of systems. However, for a company, opening its Information System to the "world" is not insignificant in terms of security. Whether to use available services or provide its own services, new technologies have introduced new vulnerabilities and therefore new risks. Our work aims to propose an approach for risk management which is based on the ISO/IEC 27005:2011 standard: we propose a development of this standard (by an extension of Annex D) so that it can fully take into account the type "service" as web services and cloud services. Indeed, a world of services is not limited to link interconnected systems, it is more a relationship between customer and supplier, where notions of trust, accountability, trace ability and governance are developed. Following this study we introduce a new security criterion, controllability, to ensure that a company keeps control of its information even if it uses such outsourced services.
  • Keywords
    IEC standards; ISO standards; Web services; cloud computing; information systems; risk management; security of data; service-oriented architecture; ISO/IEC 27005:2011 standard; SOA; Web services; accountability; cloud services; controllability; customer supplier relationship; governance; information security risk management; information system; link interconnected systems; outsourced services; security criterion; service oriented architectures; system interconnection; traceability; trust; ISO standards; Information security; Risk management; Simple object access protocol; ISO/IEC 27005; SOA; cloud; controllability; information security; risk management; web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Social Computing (SocialCom), 2013 International Conference on
  • Conference_Location
    Alexandria, VA
  • Type

    conf

  • DOI
    10.1109/SocialCom.2013.88
  • Filename
    6693385