首页 | 官方网站   微博 | 高级检索  
     


Enterprise security pattern: A model-driven architecture instance
Affiliation:1. Produban, Santander Bank, Boston, MA, USA;2. Kybele Research Group, Dept. of Computer Languages and Systems II, Rey Juan Carlos University, Madrid, Spain;3. BBVA Group, Madrid, Spain;4. Secure Systems Research Group, Dept. of Comp. and Elect. Eng. and Comp. Science, Florida Atlantic University, Boca Raton, FL, USA;5. GSyA Research Group, Dept. of Information Technologies and Systems, University of Castilla-La Mancha, Ciudad Real, Spain;1. Chief Technology Office, HP Printing and Personal Systems, Fort Collins, USA;2. Cloud and Security Lab, HP Labs, Bristol, UK;1. Korea University, Department of Chemical and Biological Engineering, Anam-dong 5-Ga, Seoungbuk-gu, Seoul 02841, Republic of Korea;2. Imperial College of London, Department of Chemical Engineering, South Kensington London SW7 2AZ, London, UK
Abstract:To secure their information assets, organizations should seek support from enterprise security architectures. Security patterns are a good way to build and test new security mechanisms, but they have some limitations related to their usability. In previous work, we defined a new type of security pattern called Enterprise Security Pattern. The main objective of these patterns is to provide an instance of model-driven architecture, which offers a solution to recurring problems that have to do with information systems security. In recent years, the hiring of Software as a Service (SaaS) from cloud providers has become very popular. There seem to be many advantages of using these services, but organizations need to be aware of a variety of threats, as well as being prepared to handle them. In another work undertaken previously, we defined an enterprise security pattern called Secure Software as a Service (Secure SaaS), which the organizations could apply to protect their information assets when using SaaS. In this paper, we present different instances of the solution models of the enterprise security pattern Secure SaaS, aiming to verify the risks that an organization would assume if each of the instances were deployed. With this approach, we intend to show how the design decisions adopted when performing the transformations between the solution models can have a direct impact on the security provided by the pattern.
Keywords:
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号