From security-by-design to the identification of security-critical deviations in process executions
Contributo in Atti di convegno
Data di Pubblicazione:
2018
Citazione:
(2018). From security-by-design to the identification of security-critical deviations in process executions . Retrieved from https://hdl.handle.net/10446/324066
Abstract:
Security-by-design is an emerging paradigm that aims to deal with security concerns from the early phases of the system development. Although this paradigm can provide theoretical guarantees that the designed system complies with the defined processes and security policies, in many application domains users are allowed to deviate from them to face unpredictable situations and emergencies. Some deviations can be harmless and, in some cases, necessary to ensure business continuity, whereas other deviations might threat central aspects of the system, such as its security. In this paper, we propose a tool supported method for the identification of security-critical deviations in process executions using compliance checking analysis. We implemented the approach as part of the STS-Tool and evaluated it using a real loan management process of a Dutch financial institute.
Tipologia CRIS:
1.4.01 Contributi in atti di convegno - Conference presentations
Elenco autori:
Salnitri, Mattia; Alizadeh, M.; Giovanella, D.; Zannone, N.; Giorgini, P.
Link alla scheda completa:
Titolo del libro:
Information Systems in the Big Data Era. CAiSE Forum 2018, Proceedings
Pubblicato in: