Elevating the Discussion on Security Management: The Data Centric Paradigm

Elevating the Discussion on Security Management: The Data Centric Paradigm
复制标题

提升安全管理讨论:以数据为中心的范式

DOI:
--
复制
发表时间:
2007
期刊:
2007 2nd IEEE/IFIP International Workshop on Business-Driven IT Management
影响因子:
--
通讯作者:
N. Zunic
N. Zunic
中科院分区:
--
文献类型:
--
作者:
T. Grandison;Michael Bilger;Luke O’Connor;M. Graf;Morton Swimmer;M. Schunter;A. Wespi;N. Zunic

文献摘要

被引文献

相似文献

Corporate decision makers have normally been disconnected from the details of the security management infrastructures of their organizations. The management of security resources has traditionally been the domain of a small group of skilled and technically savvy professionals, who report to the executive team. As threats become more prevalent, attackers get smarter and the infrastructure required to secure corporate assets become more complex, the communication gap between the decision makers and the implementers has widened. The risk of misinterpretation of corporate strategy into technical safe controls also increases with the above-mentioned trends. In this paper, we articulate a paradigm for managing enterprise security called the data centric security model (DCSM), which puts IT policy making in the hands of the corporate executives, so that security decisions can be directly executed without the diluting effect of interpretation at different levels of the Infrastructure and with the benefit of seeing direct correlation between business objective and security mechanism. Our articulation of the DCSM vision is a starting point for discussion and provides a rich platform for research into business-driven security management.