首页    期刊浏览 2024年05月19日 星期日
登录注册

文章基本信息

  • 标题:Security Policy Management Process within Six Sigma Framework
  • 本地全文:下载
  • 作者:Vijay Anand ; Jafar Saniie ; Erdal Oruklu
  • 期刊名称:Journal of Information Security
  • 印刷版ISSN:2153-1234
  • 电子版ISSN:2153-1242
  • 出版年度:2012
  • 卷号:3
  • 期号:1
  • 页码:49-58
  • DOI:10.4236/jis.2012.31006
  • 出版社:Scientific Research Publishing
  • 摘要:This paper presents a management process for creating adaptive, real-time security policies within the Six Sigma (6σ) framework. A key challenge for the creation of a management process is the integration with models of known Industrial processes. One of the most used industrial process models is Six Sigma which is a business management model wherein customer centric needs are put in perspective with business data to create an efficient system. The security policy creation and management process proposed in this paper is based on the Six Sigma model and presents a method to adapt security goals and risk management of a computing service. By formalizing a security policy management process within an industrial process model, the adaptability of this model to existing industrial tools is seamless and offers a clear risk based policy decision framework. In particular, this paper presents the necessary tools and procedures to map Six Sigma DMAIC (Define-Measure-Analyze-Improve-Control) methodology to security policy management.
  • 关键词:Security Management; Security Process; Policy; Threat; Six SIGMA
国家哲学社会科学文献中心版权所有