首页 > 最新文献

2008 3rd IEEE/IFIP International Workshop on Business-driven IT Management最新文献

英文 中文
From e-business strategy to IT resource management: A strategy-centric approach to timely scheduling web requests in B2C environments 从电子商务战略到IT资源管理:B2C环境中及时调度web请求的以战略为中心的方法
Pub Date : 2008-04-07 DOI: 10.1109/BDIM.2008.4540078
A. Beal, D. Mossé
For a B2C enterprise, resource management plays a crucial role in the achievement of business objectives. When a Web server becomes busy, and there is no control over which user requests to attend to first, negative business outcomes may result, such as a customer in the final steps of making a purchase being kept waiting and deciding to abandon the site for lack of a timely response, while less critical or urgent requests are being handled. On the other hand, if the relative value of executing different types of user requests is known, resource management mechanisms can be used to optimize the allocation of the sparsely available resources. In this paper, we introduce a methodology for estimating the value of end-user requests on a business-to-consumer (B2C) environment based on business strategy. The proposed value-estimating methodology can be used as a base for improving the allocation of e-commerce resources during peak traffic situations by maximizing the aspects of the service with more return to offer in terms of the achievement of business goals and objectives.
对于B2C企业来说,资源管理对于企业目标的实现起着至关重要的作用。当Web服务器变得繁忙,并且无法控制首先处理哪个用户请求时,可能会导致负面的业务结果,例如,在购买的最后步骤中,客户一直等待,并因缺乏及时响应而决定放弃站点,而不太重要或紧急的请求正在处理中。另一方面,如果执行不同类型的用户请求的相对价值是已知的,则可以使用资源管理机制来优化稀疏可用资源的分配。在本文中,我们介绍了一种基于业务策略估算企业对消费者(B2C)环境中最终用户请求价值的方法。建议的价值评估方法可以作为一个基础,通过最大化服务的各个方面,在实现业务目标和目的方面提供更多的回报,来改善高峰流量情况下电子商务资源的分配。
{"title":"From e-business strategy to IT resource management: A strategy-centric approach to timely scheduling web requests in B2C environments","authors":"A. Beal, D. Mossé","doi":"10.1109/BDIM.2008.4540078","DOIUrl":"https://doi.org/10.1109/BDIM.2008.4540078","url":null,"abstract":"For a B2C enterprise, resource management plays a crucial role in the achievement of business objectives. When a Web server becomes busy, and there is no control over which user requests to attend to first, negative business outcomes may result, such as a customer in the final steps of making a purchase being kept waiting and deciding to abandon the site for lack of a timely response, while less critical or urgent requests are being handled. On the other hand, if the relative value of executing different types of user requests is known, resource management mechanisms can be used to optimize the allocation of the sparsely available resources. In this paper, we introduce a methodology for estimating the value of end-user requests on a business-to-consumer (B2C) environment based on business strategy. The proposed value-estimating methodology can be used as a base for improving the allocation of e-commerce resources during peak traffic situations by maximizing the aspects of the service with more return to offer in terms of the achievement of business goals and objectives.","PeriodicalId":426943,"journal":{"name":"2008 3rd IEEE/IFIP International Workshop on Business-driven IT Management","volume":"26 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2008-04-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"130986499","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 4
A comparative study on business models of municipal wireless cities in US and Sweden 美国和瑞典市政无线城市商业模式的比较研究
Pub Date : 2008-04-07 DOI: 10.1109/BDIM.2008.4540085
Zhe Yang, Saltant Khamit, A. Mohammed, Peter Larson
In this paper, we will explore the existing operational "business models" for municipal wireless networks in US and Sweden. Based on the current paradigms of the North-American public wireless networks, we will investigate an emerging wireless city concept in Sweden to analysis this new business concept in the existing field. We will look into the relationship of different actors in various business models of the wireless cities in our selected case studies. This paper will aim to demonstrate a number of key considerations when designing and managing the business model of Municipal wireless networks as business-driven and public utility-driven services.
在本文中,我们将探讨美国和瑞典市政无线网络的现有运营“商业模式”。基于北美公共无线网络的当前范例,我们将调查瑞典新兴的无线城市概念,以分析这一新的商业概念在现有领域的应用。我们将在选定的案例研究中探讨无线城市各种商业模式中不同参与者之间的关系。本文旨在展示在设计和管理市政无线网络作为业务驱动和公用事业驱动服务的商业模式时需要考虑的一些关键因素。
{"title":"A comparative study on business models of municipal wireless cities in US and Sweden","authors":"Zhe Yang, Saltant Khamit, A. Mohammed, Peter Larson","doi":"10.1109/BDIM.2008.4540085","DOIUrl":"https://doi.org/10.1109/BDIM.2008.4540085","url":null,"abstract":"In this paper, we will explore the existing operational \"business models\" for municipal wireless networks in US and Sweden. Based on the current paradigms of the North-American public wireless networks, we will investigate an emerging wireless city concept in Sweden to analysis this new business concept in the existing field. We will look into the relationship of different actors in various business models of the wireless cities in our selected case studies. This paper will aim to demonstrate a number of key considerations when designing and managing the business model of Municipal wireless networks as business-driven and public utility-driven services.","PeriodicalId":426943,"journal":{"name":"2008 3rd IEEE/IFIP International Workshop on Business-driven IT Management","volume":"13 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2008-04-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115525463","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 5
A methodological framework for business-IT alignment 用于业务- it对齐的方法学框架
Pub Date : 2008-04-07 DOI: 10.1109/BDIM.2008.4540069
C. Ralha, Rafael Gostinski
Organizations are characterized by the usage of multiple applications and heterogeneous technological environments. Although business and IT processes are defined quite good, the processes themselves are quite different and locked in the specific application areas. As a result the language of those areas are also specific what helps to maintain the distance of the processes and make hard the mutual understanding between business and IT units. Conscious that the frequent interaction among business and IT units in any organization turned out to be the single most important factor of IT usage, this article presents a methodological framework for business-IT alignment, based on process modeling and ontology theory. The aim of the proposed methodological framework is to combine different domain ontologies - specifically business and IT, with organization processes, to achieve better organization productivity through the use of a common language.
组织的特点是使用多种应用程序和异构技术环境。尽管业务和IT流程定义得非常好,但流程本身却非常不同,并且锁定在特定的应用程序领域中。因此,这些领域的语言也是特定的,这有助于保持流程之间的距离,并使业务和IT单位之间的相互理解变得困难。意识到任何组织中业务和IT单元之间的频繁交互是IT使用的唯一最重要的因素,本文提出了一个基于流程建模和本体理论的业务-IT对齐的方法学框架。提出的方法框架的目的是将不同的领域本体(特别是业务和IT)与组织流程结合起来,通过使用公共语言来实现更好的组织生产力。
{"title":"A methodological framework for business-IT alignment","authors":"C. Ralha, Rafael Gostinski","doi":"10.1109/BDIM.2008.4540069","DOIUrl":"https://doi.org/10.1109/BDIM.2008.4540069","url":null,"abstract":"Organizations are characterized by the usage of multiple applications and heterogeneous technological environments. Although business and IT processes are defined quite good, the processes themselves are quite different and locked in the specific application areas. As a result the language of those areas are also specific what helps to maintain the distance of the processes and make hard the mutual understanding between business and IT units. Conscious that the frequent interaction among business and IT units in any organization turned out to be the single most important factor of IT usage, this article presents a methodological framework for business-IT alignment, based on process modeling and ontology theory. The aim of the proposed methodological framework is to combine different domain ontologies - specifically business and IT, with organization processes, to achieve better organization productivity through the use of a common language.","PeriodicalId":426943,"journal":{"name":"2008 3rd IEEE/IFIP International Workshop on Business-driven IT Management","volume":"55 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2008-04-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121458415","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 12
Mining semantic relations using NetFlow 使用NetFlow挖掘语义关系
Pub Date : 2008-04-07 DOI: 10.1109/BDIM.2008.4540082
A. Caracas, A. Kind, D. Gantenbein, Stefan Fussenegger, Dimitrios Dechouniotis
Knowing the dependencies among computing assets and services provides insights into the computing and business landscape, therefore, facilitating low-risk timely changes in support of a business-driven IT management. In general, the results of a dependency analysis can be used for infrastructure reengineering, show evidence of policy and process compliance, and support assessments of business resilience. Current passive discovery approaches using network monitoring analyze only direct communication between assets and provide just a single- link mesh view. This work introduces a new algorithm based on NetFlow data preprocessed by the Aurora system developed at IBM Research to create a dependency model of the network. The algorithm uses time-based event correlation and the data mining concept of association rules to detect and classify dependencies that span two or more components. The advantages of the algorithm is that no access credentials are required and no packet payload inspection is performed. The suggested algorithm populates and maintains a dependency model of an observed network that describes dependencies among computer systems, software components, and services. The model combines the mined association rules that express relations between flows into dependencies, which are given intuitive semantics. Tests with simulated and authentic data prove the accuracy of the dependency mining algorithm.
因此,了解计算资产和服务之间的依赖关系可以深入了解计算和业务环境,从而促进低风险的及时更改,以支持业务驱动的IT管理。通常,依赖性分析的结果可用于基础设施再造,显示策略和流程遵从性的证据,并支持对业务弹性的评估。目前使用网络监控的被动发现方法只分析资产之间的直接通信,并且只提供单链路网格视图。本文介绍了一种基于NetFlow数据的新算法,该算法由IBM研究院开发的Aurora系统进行预处理,以创建网络的依赖模型。该算法使用基于时间的事件关联和关联规则的数据挖掘概念来检测和分类跨越两个或多个组件的依赖关系。该算法的优点是不需要访问凭证,也不需要执行数据包负载检查。建议的算法填充并维护了一个描述计算机系统、软件组件和服务之间依赖关系的观察网络的依赖模型。该模型将挖掘的表示流之间关系的关联规则组合为依赖项,并赋予其直观的语义。仿真和真实数据验证了依赖关系挖掘算法的准确性。
{"title":"Mining semantic relations using NetFlow","authors":"A. Caracas, A. Kind, D. Gantenbein, Stefan Fussenegger, Dimitrios Dechouniotis","doi":"10.1109/BDIM.2008.4540082","DOIUrl":"https://doi.org/10.1109/BDIM.2008.4540082","url":null,"abstract":"Knowing the dependencies among computing assets and services provides insights into the computing and business landscape, therefore, facilitating low-risk timely changes in support of a business-driven IT management. In general, the results of a dependency analysis can be used for infrastructure reengineering, show evidence of policy and process compliance, and support assessments of business resilience. Current passive discovery approaches using network monitoring analyze only direct communication between assets and provide just a single- link mesh view. This work introduces a new algorithm based on NetFlow data preprocessed by the Aurora system developed at IBM Research to create a dependency model of the network. The algorithm uses time-based event correlation and the data mining concept of association rules to detect and classify dependencies that span two or more components. The advantages of the algorithm is that no access credentials are required and no packet payload inspection is performed. The suggested algorithm populates and maintains a dependency model of an observed network that describes dependencies among computer systems, software components, and services. The model combines the mined association rules that express relations between flows into dependencies, which are given intuitive semantics. Tests with simulated and authentic data prove the accuracy of the dependency mining algorithm.","PeriodicalId":426943,"journal":{"name":"2008 3rd IEEE/IFIP International Workshop on Business-driven IT Management","volume":"5 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2008-04-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"130334075","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 21
Adoption of business continuity planning processes in IT service management 在IT服务管理中采用业务连续性计划流程
Pub Date : 2008-04-07 DOI: 10.1109/BDIM.2008.4540071
Stewart H. C. Wan, Y. Chan
For any fault of the same severity level, traditional fault discovery and notification tools provide equal weighting from business points of view. To improve the fault correlation from business perspectives, we proposed a framework to automate network and system alerts with respect to its business service impact for proactive notification to IT operations management. This paper outlines the value of business continuity planning (BCP) during the course of service impact analysis, placing particular emphasis on the business perspective in the processes of IT service management. The framework explicitly employs BCP relevant processes in order to identify the relationships between business services and IT resources A practical case in IT operations to illustrate the concept was then conducted.
对于相同严重级别的任何故障,传统的故障发现和通知工具从业务角度提供了相同的权重。为了从业务角度改进故障相关性,我们提出了一个框架,可以根据业务服务影响自动发出网络和系统警报,以便主动通知IT运营管理。本文概述了业务连续性计划(BCP)在服务影响分析过程中的价值,特别强调了IT服务管理过程中的业务视角。该框架明确地使用了BCP相关流程,以确定业务服务和IT资源之间的关系。然后,通过IT操作中的一个实际案例来说明这一概念。
{"title":"Adoption of business continuity planning processes in IT service management","authors":"Stewart H. C. Wan, Y. Chan","doi":"10.1109/BDIM.2008.4540071","DOIUrl":"https://doi.org/10.1109/BDIM.2008.4540071","url":null,"abstract":"For any fault of the same severity level, traditional fault discovery and notification tools provide equal weighting from business points of view. To improve the fault correlation from business perspectives, we proposed a framework to automate network and system alerts with respect to its business service impact for proactive notification to IT operations management. This paper outlines the value of business continuity planning (BCP) during the course of service impact analysis, placing particular emphasis on the business perspective in the processes of IT service management. The framework explicitly employs BCP relevant processes in order to identify the relationships between business services and IT resources A practical case in IT operations to illustrate the concept was then conducted.","PeriodicalId":426943,"journal":{"name":"2008 3rd IEEE/IFIP International Workshop on Business-driven IT Management","volume":"56 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2008-04-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"133249780","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 10
Dynamic management of outsourced service processes’ QoS in a service provider - service supplier environment 服务提供者-服务提供者环境下外包服务过程QoS的动态管理
Pub Date : 2008-04-07 DOI: 10.1109/BDIM.2008.4540077
G. Grabarnik, Heiko Ludwig, L. Shwartz
IT service providers typically must comply with service level agreements that are part of their usage contracts with customers. Not only IT infrastructure is subject to service level guarantees such as availability or response time but also service management processes as defined by the IT Infrastructure Library (ITIL) such as change and incident processes and the fulfillment of service requests. SLAs relating to service management processes typically address metrics such as initial response time and fulfillment time. Large service providers have the choice of which internal service delivery team or external service provider they assign to parts of a service process, each provider having different costs or prices associated with it for different turn-around times at different risk. This choice in QoS and cost of different service providers can be used to manage the trade-off between penalty costs and fulfillment cost. This paper proposes a model as a basis for service provider choice at process runtime, taking into account the progress of a process so far and the availability of service capacity at service suppliers. This model can be used to reduce total service costs of IT service providers deciding on alternative delivery teams and external service providers when needed and based on current process performance.
IT服务提供商通常必须遵守服务水平协议,这是他们与客户签订的使用合同的一部分。不仅IT基础设施受服务级别保证(如可用性或响应时间)的约束,而且还受IT基础设施库(ITIL)定义的服务管理流程(如更改和事件流程以及服务请求的实现)的约束。与服务管理流程相关的sla通常处理诸如初始响应时间和实现时间之类的度量。大型服务提供商可以选择将内部服务交付团队或外部服务提供商分配给服务流程的各个部分,每个提供商对于不同的周转时间和不同的风险具有不同的成本或价格。这种QoS和不同服务提供商成本的选择可以用来管理惩罚成本和履行成本之间的权衡。本文提出了一个模型,作为流程运行时服务提供者选择的基础,考虑到流程到目前为止的进度和服务提供者服务能力的可用性。此模型可用于降低IT服务提供商在需要时根据当前流程性能决定替代交付团队和外部服务提供商的总服务成本。
{"title":"Dynamic management of outsourced service processes’ QoS in a service provider - service supplier environment","authors":"G. Grabarnik, Heiko Ludwig, L. Shwartz","doi":"10.1109/BDIM.2008.4540077","DOIUrl":"https://doi.org/10.1109/BDIM.2008.4540077","url":null,"abstract":"IT service providers typically must comply with service level agreements that are part of their usage contracts with customers. Not only IT infrastructure is subject to service level guarantees such as availability or response time but also service management processes as defined by the IT Infrastructure Library (ITIL) such as change and incident processes and the fulfillment of service requests. SLAs relating to service management processes typically address metrics such as initial response time and fulfillment time. Large service providers have the choice of which internal service delivery team or external service provider they assign to parts of a service process, each provider having different costs or prices associated with it for different turn-around times at different risk. This choice in QoS and cost of different service providers can be used to manage the trade-off between penalty costs and fulfillment cost. This paper proposes a model as a basis for service provider choice at process runtime, taking into account the progress of a process so far and the availability of service capacity at service suppliers. This model can be used to reduce total service costs of IT service providers deciding on alternative delivery teams and external service providers when needed and based on current process performance.","PeriodicalId":426943,"journal":{"name":"2008 3rd IEEE/IFIP International Workshop on Business-driven IT Management","volume":"15 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2008-04-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"125558107","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 10
On tool support for Service Level Management: From requirements to system specifications 关于服务水平管理的工具支持:从需求到系统规范
Pub Date : 2008-04-07 DOI: 10.1109/BDIM.2008.4540076
T. Schaaf, M. Brenner
Service level management (SLM) is a vital discipline in customer-oriented IT service management. Covering technical as well as organizational and economic aspects, this multi-dimensional management area has become even more important against the background of the business-driven IT management (BDIM) paradigm. Today, tools and management solutions available for SLM face three major challenges: First, the lack of an established platform-independent model (PIM) for SLM entails the existence of hard- to-integrate "islands" of support tools and makes an integrated approach to SLM tool support all but impossible. Secondly, the current solutions are mostly focused on SLA-speciflc issues, neglecting significant SLM responsibilities such as the deployment of service catalogs. Lastly, the limited perspective of many existing SLM solutions disregards the important links between SLM-related management tasks and those of other management disciplines such as fault or performance management. This paper presents first results of ongoing research aiming at developing a practicable, integrated solution for SLM, addressing above mentioned challenges. To this end, essential requirements are pointed out, and four common modules of a management architecture for SLM are outlined.
服务水平管理(SLM)是面向客户的IT服务管理中的一门重要学科。这个多维管理领域涵盖了技术、组织和经济方面,在业务驱动的IT管理(BDIM)范式的背景下变得更加重要。今天,用于SLM的工具和管理解决方案面临着三个主要挑战:首先,缺乏已建立的用于SLM的与平台无关的模型(PIM)导致了难以集成的支持工具“孤岛”的存在,并且使得集成的方法几乎不可能支持SLM工具。其次,当前的解决方案主要关注于sla特定的问题,而忽略了重要的SLM职责,例如服务目录的部署。最后,许多现有的SLM解决方案的局限性忽视了与SLM相关的管理任务与其他管理学科(如故障或性能管理)之间的重要联系。本文介绍了正在进行的研究的第一个结果,旨在为SLM开发一个切实可行的集成解决方案,解决上述挑战。为此,指出了基本需求,并概述了SLM管理体系结构的四个常见模块。
{"title":"On tool support for Service Level Management: From requirements to system specifications","authors":"T. Schaaf, M. Brenner","doi":"10.1109/BDIM.2008.4540076","DOIUrl":"https://doi.org/10.1109/BDIM.2008.4540076","url":null,"abstract":"Service level management (SLM) is a vital discipline in customer-oriented IT service management. Covering technical as well as organizational and economic aspects, this multi-dimensional management area has become even more important against the background of the business-driven IT management (BDIM) paradigm. Today, tools and management solutions available for SLM face three major challenges: First, the lack of an established platform-independent model (PIM) for SLM entails the existence of hard- to-integrate \"islands\" of support tools and makes an integrated approach to SLM tool support all but impossible. Secondly, the current solutions are mostly focused on SLA-speciflc issues, neglecting significant SLM responsibilities such as the deployment of service catalogs. Lastly, the limited perspective of many existing SLM solutions disregards the important links between SLM-related management tasks and those of other management disciplines such as fault or performance management. This paper presents first results of ongoing research aiming at developing a practicable, integrated solution for SLM, addressing above mentioned challenges. To this end, essential requirements are pointed out, and four common modules of a management architecture for SLM are outlined.","PeriodicalId":426943,"journal":{"name":"2008 3rd IEEE/IFIP International Workshop on Business-driven IT Management","volume":"15 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2008-04-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121613420","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 15
IT confidentiality risk assessment for an architecture-based approach 基于体系结构方法的IT机密性风险评估
Pub Date : 2008-01-25 DOI: 10.1109/BDIM.2008.4540072
Ayse Morali, E. Zambon, S. Etalle, Paul L. O. Re
Information systems require awareness of risks and a good understanding of vulnerabilities and their exploitations. In this paper, we propose a novel approach for the systematic assessment and analysis of confidentiality risks caused by disclosure of operational and functional information. The approach is based on a model integrating information assets and the IT infrastructure that they rely on for distributed systems. IT infrastructures enable one to analyse risk propagation possibilities and calculate the impact of confidentiality incidents. Furthermore, our approach is a mean to bridge the technical and business- oriented views of information systems, since the importance of information assets, which is leading the technical decisions, is set by the business.
信息系统需要有风险意识,对漏洞及其利用有很好的理解。在本文中,我们提出了一种系统评估和分析操作和功能信息披露所带来的保密风险的新方法。该方法基于一个模型,该模型集成了分布式系统所依赖的信息资产和IT基础设施。IT基础设施使人们能够分析风险传播的可能性,并计算机密事件的影响。此外,我们的方法是连接信息系统的技术和面向业务的观点的一种方法,因为引导技术决策的信息资产的重要性是由业务设定的。
{"title":"IT confidentiality risk assessment for an architecture-based approach","authors":"Ayse Morali, E. Zambon, S. Etalle, Paul L. O. Re","doi":"10.1109/BDIM.2008.4540072","DOIUrl":"https://doi.org/10.1109/BDIM.2008.4540072","url":null,"abstract":"Information systems require awareness of risks and a good understanding of vulnerabilities and their exploitations. In this paper, we propose a novel approach for the systematic assessment and analysis of confidentiality risks caused by disclosure of operational and functional information. The approach is based on a model integrating information assets and the IT infrastructure that they rely on for distributed systems. IT infrastructures enable one to analyse risk propagation possibilities and calculate the impact of confidentiality incidents. Furthermore, our approach is a mean to bridge the technical and business- oriented views of information systems, since the importance of information assets, which is leading the technical decisions, is set by the business.","PeriodicalId":426943,"journal":{"name":"2008 3rd IEEE/IFIP International Workshop on Business-driven IT Management","volume":"57 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2008-01-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"131369007","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 9
期刊
2008 3rd IEEE/IFIP International Workshop on Business-driven IT Management
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1