Please use this identifier to cite or link to this item: https://doi.org/10.21256/zhaw-30377
Full metadata record
DC FieldValueLanguage
dc.contributor.authorTrammell, Ariane-
dc.contributor.authorGehring, Benjamin-
dc.contributor.authorIsele, Marco-
dc.contributor.authorSpielmann, Yvo-
dc.contributor.authorZahnd, Valentin-
dc.date.accessioned2024-03-27T12:25:57Z-
dc.date.available2024-03-27T12:25:57Z-
dc.date.issued2024-
dc.identifier.isbn978-989-758-683-5de_CH
dc.identifier.urihttps://digitalcollection.zhaw.ch/handle/11475/30377-
dc.description.abstractSecuring a company is not an easy task. Many organizations such as NIST, CIS, or ISO offer frameworks that offer comprehensive security measures. However, those frameworks are generally large and require expert knowledge to be tailored to a given organization. Since such experts are rare, we propose an automated solution that selects security controls and prioritizes them according to an organizations need. We performed initial steps towards the implementation of the proposed solution by evaluating how Natural Language Processing can be used to select security controls that are relevant for the assets of a company and by showing that we can prioritize the selected controls based on the current threat landscape. We expect the proposed solution to be a major benefit for all organizations that intend to improve their security posture but are limited in specialized personnel.de_CH
dc.language.isoende_CH
dc.publisherSciTePressde_CH
dc.rightshttp://creativecommons.org/licenses/by-nc-nd/4.0/de_CH
dc.subjectSecurity managementde_CH
dc.subjectSecurity controlde_CH
dc.subjectGovernance risk and compliance (GRC)de_CH
dc.subjectAutomationde_CH
dc.subject.ddc005: Computerprogrammierung, Programme und Datende_CH
dc.subject.ddc658: Allgemeines Managementde_CH
dc.titleTowards automated information security governancede_CH
dc.typeKonferenz: Paperde_CH
dcterms.typeTextde_CH
zhaw.departementSchool of Engineeringde_CH
zhaw.organisationalunitInstitut für Informatik (InIT)de_CH
dc.identifier.doi10.5220/0012357500003648de_CH
dc.identifier.doi10.21256/zhaw-30377-
zhaw.conference.details10th International Conference on Information Systems Security and Privacy (ICISSP), Rome, Italy, 26-28 February 2024de_CH
zhaw.funding.euNode_CH
zhaw.originated.zhawYesde_CH
zhaw.pages.end127de_CH
zhaw.pages.start120de_CH
zhaw.publication.statuspublishedVersionde_CH
zhaw.publication.reviewPeer review (Publikation)de_CH
zhaw.title.proceedingsProceedings of the 10th International Conference on Information Systems Security and Privacy - ICISSPde_CH
zhaw.webfeedInformation Securityde_CH
zhaw.funding.zhawAutomated Information Security Governance and Risk Managementde_CH
zhaw.author.additionalNode_CH
zhaw.display.portraitYesde_CH
Appears in collections:Publikationen School of Engineering

Files in This Item:
File Description SizeFormat 
2024_Trammell-etal_Towards-automated-information-security-governance.pdf493.42 kBAdobe PDFThumbnail
View/Open
Show simple item record
Trammell, A., Gehring, B., Isele, M., Spielmann, Y., & Zahnd, V. (2024). Towards automated information security governance [Conference paper]. Proceedings of the 10th International Conference on Information Systems Security and Privacy - ICISSP, 120–127. https://doi.org/10.5220/0012357500003648
Trammell, A. et al. (2024) ‘Towards automated information security governance’, in Proceedings of the 10th International Conference on Information Systems Security and Privacy - ICISSP. SciTePress, pp. 120–127. Available at: https://doi.org/10.5220/0012357500003648.
A. Trammell, B. Gehring, M. Isele, Y. Spielmann, and V. Zahnd, “Towards automated information security governance,” in Proceedings of the 10th International Conference on Information Systems Security and Privacy - ICISSP, 2024, pp. 120–127. doi: 10.5220/0012357500003648.
TRAMMELL, Ariane, Benjamin GEHRING, Marco ISELE, Yvo SPIELMANN und Valentin ZAHND, 2024. Towards automated information security governance. In: Proceedings of the 10th International Conference on Information Systems Security and Privacy - ICISSP. Conference paper. SciTePress. 2024. S. 120–127. ISBN 978-989-758-683-5
Trammell, Ariane, Benjamin Gehring, Marco Isele, Yvo Spielmann, and Valentin Zahnd. 2024. “Towards Automated Information Security Governance.” Conference paper. In Proceedings of the 10th International Conference on Information Systems Security and Privacy - ICISSP, 120–27. SciTePress. https://doi.org/10.5220/0012357500003648.
Trammell, Ariane, et al. “Towards Automated Information Security Governance.” Proceedings of the 10th International Conference on Information Systems Security and Privacy - ICISSP, SciTePress, 2024, pp. 120–27, https://doi.org/10.5220/0012357500003648.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.