Towards the entri framework: Security risk management enhanced by the use of enterprise architectures

9Citations
Citations of this article
38Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Secure information systems engineering is currently a critical but complex concern. Risk management has become a standard approach to deal with the necessary trade-offs between expected security level and control cost. However, with the current interconnection between information systems combined with the increasing regulation and compliance requirements, it is more and more difficult to achieve real information security governance. Given that risk management is not able to deal with this complexity alone, we claim that a connection with Enterprise Architecture Management (EAM) contributes in addressing the above challenges, thereby sustaining governance and compliance in organisations. In this paper, we motivate the added value of EAM to improve security risk management and propose a research agenda towards a complete framework integrating both domains.

Cite

CITATION STYLE

APA

Mayer, N., Grandry, E., Feltus, C., & Goettelmann, E. (2015). Towards the entri framework: Security risk management enhanced by the use of enterprise architectures. In Lecture Notes in Business Information Processing (Vol. 215, pp. 459–469). Springer Verlag. https://doi.org/10.1007/978-3-319-19243-7_42

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free