Risk Management in Service-Oriented Information Systems
Mont de Marsan (Landes), France, 16-18 septembre 2013
Poster presentation
The interconnection of information systems is a reality, in particular with the development of service-oriented architectures (SOA) as they allow the creation of new services by composing (orchestration, choreography) existing services on the Internet. These services may have very diverse functionalities: computation, data storage, consulting remote information (catalogues, timetables). Web services (WS) are one of the most used technologies currently for such architectures.
After detailing the different technologies implemented in securing these web services, we propose an innovative approach implementing a risk management related to the use of these services. This approach relies on the ISO/IEC 27005:2011 standard which we intend to extend to services.
The design of infrastructures relying on external services is not without raising problems regarding information systems security (ISS). This concerns not only the classic criteria of confidentiality, integrity and availability, but also notions such as traceability or trust, with controllability of information as a corollary.

I have been teaching at the University of Pau and the Pays de l’Adour since 1994 and more particularly at the IUT des Pays de l’Adour on the Pau site.
My teaching activities take place mainly in the field of Computer Science and Automation with students in Thermal Engineering and Energy (GTE).
My research activity takes place in the Computer Science Laboratory of the University of Pau and the Pays de l’Adour (LIUPPA) in the ASCP team.