• DocumentCode
    2927353
  • Title

    Elevating the Discussion on Security Management: The Data Centric Paradigm

  • Author

    Grandison, Tyrone ; Bilger, Michael ; O´Connor, Luke ; Graf, Marcel ; Swimmer, Morton ; Schunter, Matthias ; Wespi, Andreas ; Zunic, Nev

  • Author_Institution
    IBM Almaden Res. Center, San Jose
  • fYear
    2007
  • fDate
    21-21 May 2007
  • Firstpage
    84
  • Lastpage
    93
  • Abstract
    Corporate decision makers have normally been disconnected from the details of the security management infrastructures of their organizations. The management of security resources has traditionally been the domain of a small group of skilled and technically savvy professionals, who report to the executive team. As threats become more prevalent, attackers get smarter and the infrastructure required to secure corporate assets become more complex, the communication gap between the decision makers and the implementers has widened. The risk of misinterpretation of corporate strategy into technical safe controls also increases with the above-mentioned trends. In this paper, we articulate a paradigm for managing enterprise security called the data centric security model (DCSM), which puts IT policy making in the hands of the corporate executives, so that security decisions can be directly executed without the diluting effect of interpretation at different levels of the Infrastructure and with the benefit of seeing direct correlation between business objective and security mechanism. Our articulation of the DCSM vision is a starting point for discussion and provides a rich platform for research into business-driven security management.
  • Keywords
    DP management; decision making; security of data; IT policy making; business-driven security management; corporate decision making; enterprise data centric security model; Computer hacking; Computer security; Costs; Data privacy; Data security; Financial management; Information security; Protection; Resource management; Technology management; Data security; Management decision-making; Resource Management; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Business-Driven IT Management, 2007. BDIM '07. 2nd IEEE/IFIP International Workshop on
  • Conference_Location
    Munich
  • Print_ISBN
    1-4244-1295-1
  • Type

    conf

  • DOI
    10.1109/BDIM.2007.375015
  • Filename
    4261104