"Security Gap" as a metric for enterprise business processes

SECURITY AND PRIVACY(2022)

引用 0|浏览0
暂无评分
摘要
Security is becoming an indispensable factor for the well-being of an enterprise. Enterprises are making huge investments to fulfill the demand for security. A big challenge faced by an enterprise while securing itself is to find the gap between the demand for security and the actual security status. Finding out a consistent metric for measuring this gap can enable security administrators to utilize the allocated funds more appropriately. Popular control gap analysis methods practiced in enterprises are mostly subjective in nature and results in imprecise measurements. To address this issue, a novel security metric "Security Gap" is introduced in this paper. This metric finds out the business process-level insecurity from the security requirements and the estimated security. The methodology uses business process modeling, attack graph modeling, and relevant base metrics to compute Security Gap.
更多
查看译文
关键词
attack graph, business process model, business process security, CVSS, security measurement, security metric, security requirement
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要