The Governance, Risk, and Compliance (GRC) management process for Information Security is a necessity for any software systems where important information is collected, processed, and used. To this extent, many standards for security managements at operational level exists (e.g., ITIL, ISO27K family etc). What is often missing is a process to govern security at organizational level. In this tutorial, we present a method to analyze and design security controls that capture the organizational setting of the system and where business goals and processes are the main citizen. The SI*-GRC method is a comprehensive method that is composed of i) a modeling framework based on a requirement engineering framework, with some extensions related to security & GRC concerns, such as: trust, permission, risk, and treatment, 2) a analysis process defining systematical steps in analyzing and design security controls, 3) analytical techniques to verify that certain security properties are satisfied and t...

A method for security governance, risk, and compliance (GRC): A goal-process approach / Asnar, Yudistira Dwi Wardhana; Massacci, Fabio. - STAMPA. - 6858:(2011), pp. 152-184. [10.1007/978-3-642-23082-0_6]

A method for security governance, risk, and compliance (GRC): A goal-process approach

Asnar, Yudistira Dwi Wardhana;Massacci, Fabio
2011-01-01

Abstract

The Governance, Risk, and Compliance (GRC) management process for Information Security is a necessity for any software systems where important information is collected, processed, and used. To this extent, many standards for security managements at operational level exists (e.g., ITIL, ISO27K family etc). What is often missing is a process to govern security at organizational level. In this tutorial, we present a method to analyze and design security controls that capture the organizational setting of the system and where business goals and processes are the main citizen. The SI*-GRC method is a comprehensive method that is composed of i) a modeling framework based on a requirement engineering framework, with some extensions related to security & GRC concerns, such as: trust, permission, risk, and treatment, 2) a analysis process defining systematical steps in analyzing and design security controls, 3) analytical techniques to verify that certain security properties are satisfied and t...
2011
Foundations of security analysis and design VI
Berlin
Springer Verlag
9783642230813
Asnar, Yudistira Dwi Wardhana; Massacci, Fabio
A method for security governance, risk, and compliance (GRC): A goal-process approach / Asnar, Yudistira Dwi Wardhana; Massacci, Fabio. - STAMPA. - 6858:(2011), pp. 152-184. [10.1007/978-3-642-23082-0_6]
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/99559
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 12
  • ???jsp.display-item.citation.isi??? ND
  • OpenAlex ND
social impact