Publications
Projects
login
About
login:
password:
Forgot your password?
Using Process Models to Analyse IT Security Requirements
Using Process Models to Analyse IT Security Requirements
Publication type:
phdthesis
Authors:
Susanne Röhrig
Abstract:
As more enterprises start to transfer their business processes to electronic media, the need for appropriate information security arises. In today's business the security of information systems is not only necessary to ensure business continuity and to protect one's assets from harm; some authors even state that security is also the enabler to do business at all. Unfortunately, it is difficult to specify which measures to take in order to achieve appropriate security. Security reviews or analyses to that aim are usually both tedious and expensive, because they require the knowledge of the IT systems as well as the business processes around them - even though the latter are generally not regarded explicitely. The idea pursued in this thesis is, therefore, to examine business processes descriptions in order to analyse IT security. In this thesis the relations between business process reengineering (BPR) or general process modelling and security analysis will be investigated. Mutual influences will be explained, synergies will be pointed out. Starting from this analysis, the so-called POSeM method - the main contribution of this thesis - was developed. The abbreviation POSeM denotes Process Oriented Security Models. These models are used to select appropriate security measures for a pre-defined business process. In four steps security objectives for the business process in general will be converted into a catalogue of appropriate safeguards, i.e., safeguards that have to be implemented in order to achieve the security objectives defined before. Two rule bases are used: one to ensure the consistency of the defined security objectives and another to derive appropriate security safeguards. Both can be configured to suit the user's security needs. The first step of POSeM examines the security objectives of an enterprise and the business process in general. During a second step these security objectives are broken down into security levels that will be assigned to all parts of the business process for the protection objectives confidentiality, integrity, availability and accountability. These levels are defined according to a discrete and ordered scale consisting of the values none, low, medium, high and, very high. Furthermore components can be assigned types that will later influence the security measures to be implemented for them. After explaining the method and its goals in general, a formal description of its rules and constraints is given. Its implementation is explained and illustrated. To prove the method's applicability it is exercised using an example from the e-business sector (i.e., the use of a content management system) and a detailed example process from the health care sector. A discussion of the method's use cases and advantages compared to "classical"' methods as well as further research directions will be given in the last chapter.
Title:
Using Process Models to Analyse IT Security Requirements
Year:
2003
school:
University of Zurich, Department of Informatics
actions