Making security measurable and manageable

Making security measurable and manageable
复制标题

使安全性可衡量、可管理

DOI:
--
复制
发表时间:
2008
期刊:
IEEE Military Communications Conference
影响因子:
--
通讯作者:
Robert A. Martin
Robert A. Martin
中科院分区:
--
文献类型:
--
作者:
Robert A. Martin

文献摘要

被引文献

相似文献

信息系统的安全性和完整性是大多数类型组织中的关键问题。找到更好的方法来解决这个问题是许多工业界,学术界和政府的目标。在解决这些问题方面越来越受欢迎的一种更有效的方法是使用标准的知识表示、枚举、交换格式和语言,以及共享关键合规性和一致性要求的标准方法。通过标准化和隔离其运营、开发和维护工具和流程之间的交互,组织在选择技术、解决方案和供应商方面获得了很大的自由。这些ldquomaking安全measurablerdquo举措提供了基础,为回答todaypsilas问责,效率和互操作性的需求增加,而不人为地限制了organizationpsilas解决方案的选择.
The security and integrity of information systems is a critical issue within most types of organizations. Finding better ways to address the topic is the objective of many in industry, academia, and government. One of the more effective approaches gaining popularity in addressing these issues is the use of standard knowledge representations, enumerations, exchange formats and languages, as well as sharing of standard approaches to key compliance and conformance mandates. By standardizing and segregating the interactions amongst their operational, development and sustainment tools and processes organizations gain great freedom in selecting technologies, solutions and vendors. These ldquomaking security measurablerdquo initiatives provide the foundation for answering todaypsilas increased demands for accountability, efficiency and interoperability without artificially constraining an organizationpsilas solution options.