A First Step Towards an ISO-Based Information Security Domain Ontology

Valentina Casola, Rosario Catelli, Alessandra De Benedictis · 2019

The need for Information Security Management Systems (SIEMs) has increased the effort requested to companies to improve the security level of their systems and their compliance with national and international standards. Unfortunately, the existence of several different security standards to comply with and the lack of well-defined guidelines related to documents preparation and reporting, may result into a bad security management and may cause several security issues. In this paper, we introduce a modeling approach to the definition of a SIEM that leverages a double-layered ontology: it is composed of a highlevel ontology, used to model complex relations among domains, and of a low-level, domain-specific ontology, aimed at modeling the ISO 27000 family of standards.

Read the paper · More papers on PaperTik