6 found
Order:
See also
  1. Ontological Analysis and Redesign of Security Modeling in ArchiMate.Ítalo Oliveira, Tiago Prince Sales, João Paulo A. Almeida, Riccardo Baratella, Mattia Fumagalli & Giancarlo Guizzardi - 2022 - In The Practice of Enterprise Modeling - 15th IFIP WG 8.1 Working Conference, PoEM 2022. Springer. pp. 82-98.
    Enterprise Risk Management and security have become a fundamental part of Enterprise Architecture, so several frameworks and modeling languages have been designed to support the activities associated with these areas. Archi- Mate’s Risk and Security Overlay is one of such proposals, endorsed by The Open Group. We investigate the capabilities of the proposed security-related con- structs in ArchiMate with regard to the necessities of enterprise security modeling. Our analysis relies on a well-founded reference ontology of security to uncover ambiguity, missing (...)
    Direct download  
     
    Export citation  
     
    Bookmark   1 citation  
  2. Ontology-based security modeling in ArchiMate.Ítalo Oliveira, Tiago Prince Sales, João Paulo A. Almeida, Riccardo Baratella, Mattia Fumagalli & Giancarlo Guizzardi - forthcoming - Software and Systems Modeling.
    Enterprise Risk Management involves the process of identification, evaluation, treatment, and communication regarding risks throughout the enterprise. To support the tasks associated with this process, several frameworks and modeling languages have been proposed, such as the Risk and Security Overlay (RSO) of ArchiMate. An ontological investigation of this artifact would reveal its adequacy, capabilities, and limitations w.r.t. the domain of risk and security. Based on that, a language redesign can be proposed as a refinement. Such analysis and redesign have been (...)
    Direct download (2 more)  
     
    Export citation  
     
    Bookmark  
  3.  13
    Understanding and Modeling Prevention.Riccardo Baratella, Mattia Fumagalli, Ítalo Oliveira & Giancarlo Guizzardi - 2022 - In Renata Guizzardi, Jolita Ralyté & Xavier Franch (eds.), Research Challenges in Information Science - 16th International Conference, RCIS 2022. Cham, Svizzera: Springer. pp. 389-405.
    Prevention is a pervasive phenomenon. It is about blocking an effect before it happens or stopping it as it unfolds: vaccines prevent (the unfolding of) diseases; seat belts prevent events causing serious injuries; circuit breaks prevent the manifestation of overcurrents. Many disciplines in the information sciences deal with modeling and reasoning about prevention. Examples include risk and security management as well as medical and legal informatics. Having a proper conceptualization of this phenomenon is crucial for devising proper modeling mechanisms and (...)
    Direct download  
     
    Export citation  
     
    Bookmark   2 citations  
  4. On the Semantics of Risk Propagation.Mattia Fumagalli, Gal Engelberg, Tiago Prince Sales, Ítalo Oliveira, Dan Klein, Pnina Soffer, Riccardo Baratella & Giancarlo Guizzardi - forthcoming - In Research Challenges in Information Science - 16th International Conference, RCIS 2023. Springer.
    Risk propagation encompasses a plethora of techniques for analyzing how risk “spreads” in a given system. Albeit commonly used in technical literature, the very notion of risk propagation turns out to be a conceptually imprecise and overloaded one. This might also explain the multitude of modeling solutions that have been proposed in the lit- erature. Having a clear understanding of what exactly risk is, how it be quantified, and in what sense it can be propagated is fundamental for devising high-quality (...)
    Direct download  
     
    Export citation  
     
    Bookmark  
  5. An Ontology of Security from a Risk Treatment Perspective.Ítalo Oliveira, Tiago Prince Sales, Riccardo Baratella, Mattia Fumagalli & Giancarlo Guizzardi - 2022 - In 41th International Conference, ER 2022, Proceedings. Cham: Springer. pp. 365-379.
    In Risk Management, security issues arise from complex relations among objects and agents, their capabilities and vulnerabilities, the events they are involved in, and the value and risk they ensue to the stakeholders at hand. Further, there are patterns involving these relations that crosscut many domains, ranging from information security to public safety. Understanding and forming a shared conceptualization and vocabulary about these notions and their relations is fundamental for modeling the corresponding scenarios, so that proper security countermeasures can be (...)
    Direct download (2 more)  
     
    Export citation  
     
    Bookmark  
  6. Boosting D3FEND: Ontological analysis and recommendations.Ítalo Oliveira, Gal Engelberg, Pedro Paulo F. Barcelos, Tiago Prince Sales, Mattia Fumagalli, Riccardo Baratella, Dan Klein & Giancarlo Guizzardi - forthcoming - In Formal Ontology in Information Systems. Nieuwe Hemweg, The Netherlands: IOS Press.
    Formal Ontology is a discipline whose business is to develop formal theories about general aspects of reality such as identity, dependence, parthood, truth-making, causality, etc. A foundational ontology is a specific consistent set of these ontological theories that support activities such as domain analysis, conceptual clarification, and meaning negotiation. A (well-founded) core ontology specifies, under a foundational ontology, the central concepts and relations of a given domain. Foundational and core ontologies can be seen as ontology engineering frameworks to systematically address (...)
     
    Export citation  
     
    Bookmark