• skip to content
  • skip to navigation
  • skip to supporting content
Homepage
CLOK - Central Lancashire Online Knowledge
Menu
  • Home
  • About
  • Policies
  • Deposit Guide: Research eTheses
  • Copyright Guide
  • Contact
  • Links
    • Login
  • Deposit
  • Search Item
  • Search FullText
  • Browse

Value-driven Security Agreements in Extended Enterprises

Tools
- Tools
+ Tools

Franqueira, Virginia N.L. and Wieringa, Roel (2010) Value-driven Security Agreements in Extended Enterprises. Technical Report. Centre for Telematics and Information Technology, University of Twente, Enschede.

[img]
Preview
PDF - Published Version
2054Kb

Abstract

Today organizations are highly interconnected in business networks called extended enterprises. This is mostly facilitated by outsourcing and by new economic models based on pay-as-you-go billing; all supported by IT-as-a-service. Although outsourcing has been around for some time, what is now new is the fact that organizations are increasingly outsourcing critical business processes, engaging on complex service bundles, and moving infrastructure and their management to the custody of third parties. Although this gives competitive advantage by reducing cost and increasing flexibility, it increases security risks by eroding security perimeters that used to separate insiders with security privileges from outsiders without security privileges. The classical security distinction between insiders and outsiders is supplemented with a third category of threat agents, namely external insiders, who are not subject to the internal control of an organization but yet have some access privileges to its resources that normal outsiders do not have. Protection against external insiders requires security agreements between organizations in an extended enterprise. Currently, there is no practical method that allows security officers to specify such requirements. In this paper we provide a method for modeling an extended enterprise architecture, identifying external insider roles, and for specifying security requirements that mitigate security threats posed by these roles. We illustrate our method with a realistic example.


Item Type:Monograph (Technical Report)
Uncontrolled Keywords (separate with ;):Extended Enterprise Architecture; Governance; Security Agreement; External Insider Threat; Value Modeling
Subjects:Q Science > Q Science (General)
Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Schools:School of Computing Engineering & Physcial Sciences
ID Code:6080
Deposited By: Carmit Erez
Deposited On:05 Nov 2012 13:50
Last Modified:05 Nov 2012 13:50

Repository Staff Only: item control page

University of Central Lancashire

Preston,
Lancashire,
PR1 2HE

Tel: +44 (0)1772 201 201

Other Links

  • Contact UCLan
  • How to find us
  • Help

  • Facebook
  • Twitter
  • UCLan RSS
  • Contact UCLan
  • Copyright |
  • Disclaimer |
  • Data Protection Act |
  • Freedom of Information