Security Policy Model in a Hybrid Zachman-TOGAF Framework for a Telework Enterprise Architecture in a Cloud Environment
- 1 Equipe MAC, Laboratoire LASTIC, Ecole Supérieure Africaine des TIC (ESATIC), Abidjan, Côte d’Ivoire
- 2 Equipe MAC, Laboratoire LASTIC, Ecole Supérieure Africaine des TIC (ESATIC), Abidjan, Côte d’Ivoire
- 3 Equipe MAC, Laboratoire LASTIC, Ecole Supérieure Africaine des TIC (ESATIC), Abidjan, Côte d’Ivoire
- 4 Equipe MAC, Laboratoire LASTIC, Ecole Supérieure Africaine des TIC (ESATIC), Abidjan, Côte d’Ivoire
- 5 Departement Informatique, Institut Mines Telecom Atlantique, Brest, France
- 6 UMRI STI, Ecole Doctorale Polytechnique, Institut National Polytechnique Houphouët-Boigny, Yamoussoukro, Côte d’Ivoire
Abstract
Context and motivation: In an ever-changing post COVID-19 world, more and more businesses are adopting teleworking models, making it essential to use Cloud technology to facilitate collaboration and data accessibility. However, this transition to teleworking and the Cloud poses major challenges in terms of the security of organization’s information systems. Protecting sensitive data and IT systems is becoming an absolute priority to guarantee business continuity and prevent potential cyber threats and attacks. Security policies need to be put in place. Problem: Within a Hybrid Zachman-TOGAF Framework for an Enterprise Architecture exploiting Cloud technology in a teleworking context, several problems arise, including: How can the confidentiality, integrity and availability of the company’s critical data be ensured in a teleworking environment using Cloud solutions? Objective and methodology: With this in mind, this article proposes a systemic approach based on a mathematical optimization model to identify, assess and manage information security risks under budgetary constraints to ensure adequate protection of confidential data. The aim is to create a secure, reliable and resilient working environment, where employees can access the necessary resources with confidence, even outside the organization’s premises. Results: The approach proposed in this article shows how a mathematical model can be used to optimize security decisions in a cloud environment within a dedicated teleworking enterprise architecture. By integrating these results into a hybrid Zachman-TOGAF Framework, the organization can align its security strategies with its business objectives, while respecting budgetary constraints and minimizing risk. In addition, Monte Carlo simulations over 10,000 iterations to assess variations in residual risk as a function of fluctuations in threat probabilities and the costs of security measures in the same mathematical model show a trade-off between the cost of implementing the security measure, budget availability and residual risk, which is an aid to decision-making and strategic choices for the system operating in the organization in terms of information system security.
- Cybersector (2024) Data Breach, What Cost, Impact and Mitigation Measures for Your Business in 2024. https://cyberspector.com/violation-des-donnees-quel-cout-impact-et-mesures-dattenuation-pour-votre-entreprise-en-2024/
- Donald, L.P. (2000) Information Systems Security, Global Corporate Protection. Campus Press.
- Barbara, G and Edward, R. (1995) An Introduction to Computer Security: The NIST Handbook. https://doi.org/10.6028/NIST.SP.800-1
- Bell, D.E. and LaPadula, L.J. (1976) Secure Computer Systems: Unified Exposition and Multics Interpretation. Technical Report, MTR 2997 Rev. 1, MITRE Corp.
- Biba, K.J. (1977) Integrity Consideration for Secure Computer Systems. The MITRE Corporation, Technical Report ESD-TR-76-372 & MTR-3153.
- Clark, D.D. and Wilson, D.R. (1987) A Comparison of Commercial and Military Computer Security Policies. 1987 IEEE Symposium on Security and Privacy , Oakland, 27-29 April 1987, 184. https://doi.org/10.1109/sp.1987.10001
- Brewer, D.F.C. and Nash, M.J. (1989) The Chinese Wall Security Policy. Proceed ings 1989 IEEE Symposium on Security and Privacy , Oakland, 1-3 May 1989, 206-214. https://doi.org/10.1109/secpri.1989.36295
- Ismail, W.B.W., Widyarto, S., Adiyarta, K., Syafrullah, M. and Tajuddin, L.M. (2022) An Information Security Policy Development Process in Higher Education Institution: A Case Study Approach. 2022 9 th International Conference on Electrical Engineering , Computer Science and Informatics ( EECSI ), Jakarta, 6-7 October 2022, 147-152. https://doi.org/10.23919/eecsi56542.2022.9946593
- Angraini, Alinda Alias, R. and Okfalisa, O. (2019) Need for Compliance with Information Security Policy in Universities: A Preliminary Survey. 2019 Fourth International Conference on Informatics and Computing ( ICIC ), Semarang, 16-17 October 2019, 1-6. https://doi.org/10.1109/icic47613.2019.8985949
- Mohammed, A., Kumar, S., Mu'Azu, H.G., Kumar, R., Shah, P., Memoria, M., et al . (2022) Data Security and Protection: A Mechanism for Managing Data Theft and Cybercrime in Online Platforms of Educational Institutions. 2022 International Confer ence on Machine Learning , Big Data , Cloud and Parallel Computing ( COM - IT - CON ), Faridabad, 26-27 May 2022, 758-761. https://doi.org/10.1109/com-it-con54601.2022.9850702
- Almubayedh, D., khalis, M.A., Alazman, G., Alabdali, M., Al-Refai, R. and Nagy, N. (2018) Security Related Issues in Saudi Arabia Small Organizations: A Saudi Case Study. 2018 21 st Saudi Computer Society National Computer Conference ( NCC ), Riyadh, 25-26 April 2018, 1-6. https://doi.org/10.1109/ncg.2018.8593058