IT Security Risk Analysis based on Business Process Models enhanced with Security Requirements.

Stefan Taubenberger, Jan Jürjens · 2008

Abstract: Traditional risk analysis approaches are based on events, probabilities and impacts. They are complex, time-consuming, and costly, and have limitations regarding the data and assessment quality: First, security events have to be identified often without much methodological guidance, making the process prone to errors and omissions. Second, concrete probability values for these events usually have to be provided, and these are not available in practice to a satisfactory degree of precision and reliability. We propose an approach for risk analysis based on business process models enhanced with security requirements and information about critical processes as well as organizational and system boundaries. This approach bypasses these limitations: security risk events can be derived from the business process models together with the security requirements, and probabilities do not have to be provided. The approach is illustrated using a business process model derived from business practice.

Read the paper · More papers on PaperTik