Design of algorithms for automated collection of IT assets

Michal Sterbak, Pavel Segeč, Jan Jurc · 2022 20th International Conference on Emerging eLearning Technologies and Applications (ICETA) · 2022

The main goal of information security is compliance with established security policies, norms, and standards. Maintaining and improving security affects all business aspects from infrastructure to information itself. All computing entities such as routers, switches, cloud storage, firewalls, servers, databases or software and information can be called by one name, IT assets. All these IT assets must be protected in terms of integrity, availability, and confidentiality. These three aspects are addressed in the risk management process for the purpose of information security. Risk management is closely related to information security, and it is relatively complex and expensive activity. In most cases, even today, the risk management and information security are approached manually. In addition, various software is also used that partially facilitate some sub-processes, but still require manual human intervention to operate them to achieve the desired outputs. In this study, we focus on one of the basic sub-processes of information security management, namely the identification of IT assets, which is the basis of the entire process. We will describe new algorithms for efficient and automated collection of IT assets gathered over the network. At the end of the study, we address and describe the possible use of collected information and its connection to the IT asset assessment sub-process, which is another of the information security risk management sub-processes.

Read the paper · More papers on PaperTik