Security audit of data flows across enterprise systems and networksстатья
Информация о цитировании статьи получена из
Scopus
Дата последнего поиска статьи во внешних источниках: 27 января 2016 г.
-
Авторы:
Joukov N.,
Shorokhov V.,
Tantsuyev D.
-
Сборник:
2014 9th International Conference for Internet Technology and Secured Transactions, ICITST 2014
-
Год издания:
2014
-
Место издания:
Institute of Electrical and Electronics Engineers Inc
-
Первая страница:
240
-
Последняя страница:
247
-
DOI:
10.1109/ICITST.2014.7038813
-
Аннотация:
Enterprise IT environments are heterogeneous and complex with dozens of important software components running on each server and exchanging data with other servers, point of sale terminals, kiosks, door locks, workstations, and other systems. It is necessary to identify and document critical data flows across these systems and networks and create and verify corresponding security perimeters. Thus, newly adopted payment card industry data security standard version 3 requires data flows documentation across systems and networks, which is hard to maintain manually. In this paper, we describe the design of an automated and scalable data flows identification and diagramming system that relies on practical information sources and software and hardware models. As a result, the system can be used for real-life security audit and planning projects in diverse real-life environments. We evaluate it in three enterprise IT environments that belong to various types of industries. © 2014 Infonomics Society.
-
Добавил в систему:
Шорохов Владислав Владимирович