Risk Management in Service-Oriented Information Systems

16 Sep 2013·
Vincent Lalanne
Vincent Lalanne
,
Manuel Munier
,
Alban Gabillon
· 1 min read
Abstract
Service-oriented architectures (SOA) offer new possibilities for the interconnection of information systems. Opening up a company’s IS to the outside world is however not harmless from a security point of view. Whether for using services offered by third parties or for offering their own, these technologies introduce new vulnerabilities in the IS and, consequently, new risks. Our work aims to initiate an approach to managing these risks that relies on a standard, the ISO/IEC 27005:2011 standard. We propose an evolution of this standard so that it can fully take the “service” type into account. Following this study we also introduce a new criterion, controllability, to qualify the security of information systems.
Type
Publication
In 8ème Conférence sur la Sécurité des Architectures Réseaux et des Systèmes d’Information (SARSSI'2013)
Location

Mont de Marsan (Landes), France, 16-18 septembre 2013

publications

Poster presentation

The interconnection of information systems is a reality, in particular with the development of service-oriented architectures (SOA) as they allow the creation of new services by composing (orchestration, choreography) existing services on the Internet. These services may have very diverse functionalities: computation, data storage, consulting remote information (catalogues, timetables). Web services (WS) are one of the most used technologies currently for such architectures.

After detailing the different technologies implemented in securing these web services, we propose an innovative approach implementing a risk management related to the use of these services. This approach relies on the ISO/IEC 27005:2011 standard which we intend to extend to services.

The design of infrastructures relying on external services is not without raising problems regarding information systems security (ISS). This concerns not only the classic criteria of confidentiality, integrity and availability, but also notions such as traceability or trust, with controllability of information as a corollary.

Vincent Lalanne
Authors
Computer science teacher and researcher

I have been teaching at the University of Pau and the Pays de l’Adour since 1994 and more particularly at the IUT des Pays de l’Adour on the Pau site.

My teaching activities take place mainly in the field of Computer Science and Automation with students in Thermal Engineering and Energy (GTE).

My research activity takes place in the Computer Science Laboratory of the University of Pau and the Pays de l’Adour (LIUPPA) in the ASCP team.