Sciweavers

CNSM
2010

CRAC: Confidentiality risk assessment and IT-infrastructure comparison

13 years 10 months ago
CRAC: Confidentiality risk assessment and IT-infrastructure comparison
Confidentiality is a critical aspect in todays Risk Assessment (RA) practices for many industrial organizations. Assessing confidentiality risks is challenging and the result of a confidentiality RA is still largely based on the subjective opinion of the risk assessor(s). The presence of cross-organization cooperations (e.g. outsourcing), makes a confidentiality RA even more challenging because there are additional threat agents to take into account (e.g. an outsourcers employee). In this paper we present CRAC, an IT infrastructure-based method for assessing and comparing confidentiality risks of IT based collaborations. The method determines confidentiality risks by taking into account the effects of the leakage of confidential information (e.g. industrial secrets and user credentials), and the paths that may be followed by different attackers (e.g. insider, outsider and outsourcer). We also show how the CRAC-method can be applied in practice and we evaluate its effectiveness by
Ayse Morali, Emmanuele Zambon, Sandro Etalle, Roel
Added 10 Feb 2011
Updated 10 Feb 2011
Type Journal
Year 2010
Where CNSM
Authors Ayse Morali, Emmanuele Zambon, Sandro Etalle, Roel Wieringa
Comments (0)