Towards an advanced enterprise it security engineering
Vers une Ingénierie Avancée de la Sécurité des SI d'entreprise
Wilson Goudalo,
Christophe Kolski () and
Frédéric Vanderhaegen ()
Additional contact information
Wilson Goudalo: LAMIH - Laboratoire d'Automatique, de Mécanique et d'Informatique industrielles et Humaines - UMR 8201 - UVHC - Université de Valenciennes et du Hainaut-Cambrésis - CNRS - Centre National de la Recherche Scientifique
Christophe Kolski: LAMIH - Laboratoire d'Automatique, de Mécanique et d'Informatique industrielles et Humaines - UMR 8201 - UVHC - Université de Valenciennes et du Hainaut-Cambrésis - CNRS - Centre National de la Recherche Scientifique
Frédéric Vanderhaegen: LAMIH - Laboratoire d'Automatique, de Mécanique et d'Informatique industrielles et Humaines - UMR 8201 - UVHC - Université de Valenciennes et du Hainaut-Cambrésis - CNRS - Centre National de la Recherche Scientifique
Post-Print from HAL
Abstract:
In our era of the service industry, information systems play a prominent role. They even hold a vital position for businesses, organizations and individuals. Information systems are confronted with new security threats on an ongoing basis; these threats become more and more sophisticated and of different natures. In this context, it is important to prevent attackers from achieving their results, to manage the inevitable flaws, and to minimize their impacts. Security practices must be carried out within an engineering framework; Security engineering needs to be improved. To do this, it is proposed to develop systemic approaches, innovative on wide spectra and that work on several axes together, improving the user experience. Our goal is to jointly track down and resolve issues of security, usability and resiliency in enterprise information systems. In this paper, we position sociotechnical systems with regard to the information systems of companies and organizations. We address paradigms of sociotechnical systems and refocus on the correlations between security, usability and resilience. A case study illustrates the proposed approach. It presents the development of design patterns to improve the user experience. The article concludes with an overall discussion of the approach, as well as research perspectives. © 2017 Lavoisier.
Keywords: BPMN; Conceptual model; Design patterns; Enterprise IS; Joint analysis; Metrics; Privacy; Resilience; Security; Semantics; Sociotechnical systems; UML; Usability; User eXperience (search for similar items in EconPapers)
Date: 2017
Note: View the original document on HAL open archive server: https://uphf.hal.science/hal-03280530
References: View references in EconPapers View complete reference list from CitEc
Citations:
Published in Revue des Sciences et Technologies de l'Information - Série ISI : Ingénierie des Systèmes d'Information, 2017, 22 (1), pp.65-107. ⟨10.3166/ISI.22.1.65-107⟩
Downloads: (external link)
https://uphf.hal.science/hal-03280530/document (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:hal:journl:hal-03280530
DOI: 10.3166/ISI.22.1.65-107
Access Statistics for this paper
More papers in Post-Print from HAL
Bibliographic data for series maintained by CCSD ().