首页    期刊浏览 2024年10月06日 星期日
登录注册

文章基本信息

  • 标题:From Insider Threats to Business Processes that are Secure-by-Design
  • 本地全文:下载
  • 作者:Dieter Gollmann
  • 期刊名称:Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications
  • 印刷版ISSN:2093-5374
  • 电子版ISSN:2093-5382
  • 出版年度:2012
  • 卷号:3
  • 期号:1-2
  • 页码:4-12
  • 出版社:Innovative Information Science & Technology Research Group
  • 摘要:We argue that insider threat is a placeholder term that accompanies the transition from securing IT infrastructures to securing the socio-technical systems made possible by these IT infrastructures. The term insider in its literal interpretation loses meaning in a context where there are no stable perime- ters one can refer to. Business practices such as outsourcing, employing temporary contractors, and the very use of IT, have removed security perimeters in the search for short-term efficiency gains, which may result in mid-term losses due to increased vulnerabilities. We conclude that securing socio-technical systems calls for the design of organisational (business) processes that remain viable once inside information about their implementation becomes available to potential attackers rather than for the deployment of secure IT infrastructures
  • 关键词:Insider threats; business process; IT security
国家哲学社会科学文献中心版权所有