The increasing reliance of organisations on information systems connected to or extending over open data networks has established information security as a critical success factor for modern organisations. Risk analysis appears to be the predominant methodology for the introduction of security in information systems (IS). However, risk analysis is based on a very simple model of IS as consisting of assets, mainly data, hardware and software, which are vulnerable to various threats. Thus, risk analysis cannot provide for an understanding of the organisational environment in which IS operate. We believe that a comprehensive methodology for information systems security analysis and design (IS‐SAD) should incorporate both risk analysis and organisational analysis, based on business process modelling (BPM) techniques. This paper examines the possible contribution of BPM techniques to IS‐SAD and identifies the conceptual and methodological requirements for a technique to be used in this context. Based on these requirements, several BPM techniques have been reviewed. The review reveals the need for either adapting and combining current techniques or developing new, specialised ones.
Article navigation
1 August 2000
This article was originally published in
Information Management & Computer Security
Literature Review|
August 01 2000
The use of business process modelling in information systems security analysis and design
S.A. Kokolakis;
S.A. Kokolakis
Department of Informatics, Athens University of Economics and Business, Athens, Greece
Search for other works by this author on:
A.J. Demopoulos;
A.J. Demopoulos
Department of Informatics, Athens University of Economics and Business, Athens, Greece
Search for other works by this author on:
E.A. Kiountouzis
E.A. Kiountouzis
Department of Informatics, Athens University of Economics and Business, Athens, Greece
Search for other works by this author on:
Publisher: Emerald Publishing
Online ISSN: 1758-5805
Print ISSN: 0968-5227
© MCB UP Limited
2000
Information Management & Computer Security (2000) 8 (3): 107–116.
Citation
Kokolakis S, Demopoulos A, Kiountouzis E (2000), "The use of business process modelling in information systems security analysis and design". Information Management & Computer Security, Vol. 8 No. 3 pp. 107–116, doi: https://doi.org/10.1108/09685220010339192
Download citation file:
789
Views
New and popular articles
Suggested Reading
Towards the manufacturing enterprises of the future
International Journal of Operations & Production Management (May,1997)
A process modelling approach at Xerox of Brazil
Work Study (December,2001)
Attitudes of Australian information system managers against online attackers
Information Management & Computer Security (August,2001)
A conceptual foundation for organizational information security awareness
Information Management & Computer Security (March,2000)
Crises and revolutions in information technology: lessons learned from Y2K
Industrial Management & Data Systems (August,2002)
Related Chapters
“$40 to Make Sure”: Background Check Laws and the Endogenous Construction of Criminal Risk
After Imprisonment: Special Issue
Women and Risk: Does Takaful Have the Solution?
New Developments in Islamic Economics
Sovereign Credit Default Swap
International Financial Markets
Recommended for you
These recommendations are informed by your reading behaviors and indicated interests.
