Enabling change-driven workflows in continuous information security management
Michael Brunner, Andrea Mussmann, Ruth Breu · 2019
Information Security Management Systems (ISMS) aim at ensuring proper protection of information values and information processing systems (i.e., assets). Information Security Risk Management (ISRM) techniques are incorporated in ISMSs to deal with threats and vulnerabilities that impose risks to information security properties of these assets. The ongoing evolution of information systems as well as the ever-changing threat landscape requires enterprises to adopt new approaches to ensure the consistent compliance with their information security goals. The great challenge enterprises are facing is to efficiently deal with all changes to their assets, their risk exposure and the impact of these changes to their ISMS and ISRM activities. We present a model-based approach for continuous information security management based on semi-automated workflows triggered by changes of the underlying asset catalogue, the operational environment and the threat landscape. The prototypical implementation was evaluated in a real-world industrial setting demonstrating high usability when integrating stakeholders from different domains in a continuous risk management process.