Á. J. Varela-Vaca, R. M. Gasca, S. P. Hidalgo
2011.7.18Proceedings of the International Conference on Security and Cryptography
tlooto Summary
This framework provides innovative mechanisms based on model-based diagnosis and constraint programming in order to carry out the risk assessment of business processes and the automatic check of the conformance of security requirements.
Abstract
Several reports indicate that one of the most important business priorities is the improvement of business and IT management. Nowadays, business processes and in general service-based ones use other external services which are not under their jurisdiction. Organizations do not usually consider their exposition to security risks when business processes cross organizational boundaries. In this paper, we propose a risk-aware framework for security-quality requirements in business processes management. This framework is focused on the inclusion of security issues from design to execution. The framework provides innovative mechanisms based on model-based diagnosis and constraint programming in order to carry out the risk assessment of business processes and the automatic check of the conformance of security requirements.
Citation format
VARELA-VACA, Á. J.; GASCA, R. M.; HIDALGO, S. P. OPBUS: Risk-aware framework for the conformance of security-quality requirements in business processes. Proceedings of the International Conference on Security and Cryptography, 2011: 370–374.