On Development of Platform for Organization Security Threat Analytics and Management (POSTAM) Using Rule-Based Approach
- 1 School of Computational and Communication Science and Engineering, The Nelson Mandela African Institution of Science and Technology, Arusha, Tanzania
- 2 Faculty of Science and Technology, Mzumbe University, Morogoro, Tanzania
- 3 Faculty of Economics, North West University, Vanderbijlpark, South Africa
- 4 School of Computational and Communication Science and Engineering, The Nelson Mandela African Institution of Science and Technology, Arusha, Tanzania
Abstract
The integration of organisation’s information security policy into threat modeling enhances effectiveness of security strategies for information security management. These security policies are the ones which define the sets of security issues, controls and organisation’s commitment for seamless integration with knowledge based platforms in order to protect critical assets and data. Such platforms are needed to evaluate and share violations which can create security loop-hole. The lack of rules-based approaches for discovering potential threats at organisation’s context, poses a challenge for many organisations in safeguarding their critical assets. To address the challenge, this paper introduces a Platform for Organisation Security Threat Analytic and Management (POSTAM) using rule-based approach. The platform enhances strategies for combating information security threats and thus improves organisations’ commitment in protecting their critical assets. R scripting language for data visualization and java-based scripts were used to develop a prototype to run on web protocol. MySQL database management system was used as back-end for data storage during threat analytic processes.
- Anagement, S., Spears, B. and Barki, H. (2010) User Participation in Information Systems Security Risk Management. MIS Quarterly, 34, 503-522.
- Mbowe, J.E., Zlotnikova, I., Msanjila, S.S. and Oreku, G.S. (2014) A Conceptual Framework for Threat Assessment Based on Organization’s Information Security Policy. Journal of Information Security, 5, 166-177. https://doi.org/10.4236/jis.2014.54016
- Nielinger, O. (2003) Rural ICT Utilisation in Tanzania: Empirical Findings from Kasulu, Magu, and Sengerema. Inst. African Stud., Hamburg.
- Mijatov, S., Langer, P., Mayerhofer, T. and Kappel, G. (2013) A Framework for Testing UML Activities Based on fUML. Proceedings of the 10th International Workshop on Model Driven Engineering, Verification and Validation Co-Located with 16th International Conference on Model Driven Engineering Languages and Systems, Miami, 1 October 2013, 1-10.
- Von Solms, B. and von Solms, R. (2004) The 10 Deadly Sins of Information Security Management. Computers & Security, 23, 371-376. https://doi.org/10.1016/j.cose.2004.05.002
- Mataracioglu, T. and Ozkan, S. (2011) Governing Information Security in Conjunction with COBIT and ISO 27001. https://arxiv.org/ftp/arxiv/papers/1108/1108.2150.pdf
- Shojaie, B. and Federrath, H. (2014) Evaluating the Effectiveness of ISO 27001?: 2013 Based on Annex A. No. Fares.
- Eriksson, H., Penker, M. and Training, O. Business Modeling with UML.
- Rumbaugh, J., Jacobson, I. and Booch, G. (2004) Unified Modeling Language Reference Manual. Pearson Higher Education, New York.
- Hay, D. (2013) Data Model Patterns: Conventions of Thought. Addison-Wesley, Upper Saddle River.
- Vagias, W.M. (2006) Likert-Type Scale Response Anchors.
- Pederiva, A. (2003) The COBIT Maturity Model in a Vendor Evaluation Case. Information Systems Control Journal, 3, 26-29.
- Krisanthi, G., Sukarsa, I.M. and Bayupati, P.A. (2014) Governance Audit of Application Procurement Using COBIT Framework. Journal of Theoretical and Applied Information Technology, 59, 342-351.