information stewardship systems perspectives systems solutions n.
Download
Skip this Video
Loading SlideShow in 5 Seconds..
Information Stewardship: Systems Perspectives, Systems Solutions PowerPoint Presentation
Download Presentation
Information Stewardship: Systems Perspectives, Systems Solutions

Loading in 2 Seconds...

  share
play fullscreen
1 / 6
marcos

Information Stewardship: Systems Perspectives, Systems Solutions - PowerPoint PPT Presentation

112 Views
Download Presentation
Information Stewardship: Systems Perspectives, Systems Solutions
An Image/Link below is provided (as is) to download presentation

Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server.

- - - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - - -
Presentation Transcript

  1. Information Stewardship: Systems Perspectives, Systems Solutions David Pym University of Aberdeen Information Security Leaders, Edinburgh, 10/02/2011

  2. Information Stewardship • Information stewardship is one of the next two big challenges for security/assurance research • Stewardship goes beyond protecting CIA • Adding/protecting value; complying with and upholding values; obligation; trust • The other one is the convergence of physical and information security concepts in the Internet of Things (airport security as an information processor)

  3. Information Stewardship Lifecycle Environment: threat, economic, investment Policy: people, process, technology, operations Governance Design Revise SecurityAnalytics Analysis Assurance/situational awareness (Trusted) infrastructure

  4. Stewardship Economics • It’s all about trade-offs • For example, confidentiality and availability trade off, just like inflation and unemployment • Cost also trades off • Use utility theory to understand security trade-offs and system design • This is done for real in Security Analytics: utility theory and mathematical systems modelling yield predictive simulations in security management

  5. Satisficing Cloud Stewardship Service level Due diligence Target zone Sharing

  6. Summary • We’re making security management into a science • HP’s Security Analytics is the first (commercial) step • Stewardship presents huge challenges, in the Cloud, in the Internet of Things, … • Getting it right means doing the math, doing the economics, capturing behaviour, predicting design/investment consequences