Skip to main content

2022 | OriginalPaper | Buchkapitel

Ontological Analysis and Redesign of Security Modeling in ArchiMate

verfasst von : Ítalo Oliveira, Tiago Prince Sales, João Paulo A. Almeida, Riccardo Baratella, Mattia Fumagalli, Giancarlo Guizzardi

Erschienen in: The Practice of Enterprise Modeling

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Enterprise Risk Management and security have become a fundamental part of Enterprise Architecture, so several frameworks and modeling languages have been designed to support the activities associated with these areas. ArchiMate’s Risk and Security Overlay is one of such proposals, endorsed by The Open Group. We investigate the capabilities of the proposed security-related constructs in ArchiMate with regard to the necessities of enterprise security modeling. Our analysis relies on a well-founded reference ontology of security to uncover ambiguity, missing modeling elements, and other deficiencies of the security modeling capabilities in ArchiMate. Based on this ontologically-founded analysis, we propose a redesign of security aspects of ArchiMate to overcome its original limitations.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Fußnoten
1
Files related to ROSE can be found in the following public repository: https://​github.​com/​unibz-core/​security-ontology.
 
2
Actually, we can wonder whether the distinction of several of ArchiMate’s Motivation Elements is (or not) redundant, such as goal, outcome, requirement, and principle, but this issue is outside the scope of our paper.
 
3
Naturally, employing the theory of prevention in ArchiMate requires adaptation, considering ArchiMate does not distinguish the instance level from the type level.
 
Literatur
1.
Zurück zum Zitat Band, I., et al.: How to model enterprise risk management and security with the archimate language. The Open Group white paper (W172), vol. 9 (2019) Band, I., et al.: How to model enterprise risk management and security with the archimate language. The Open Group white paper (W172), vol. 9 (2019)
2.
Zurück zum Zitat Baratella, R., Fumagalli, M., Oliveira, Í., Guizzardi, G.: Understanding and modeling prevention. In: Guizzardi, R., Ralyte, J., Franch, X. (eds.) International Conference on Research Challenges in Information Science, LNBIP, vol. 446, pp. 389–405. Springer (2022). https://doi.org/10.1007/978-3-031-05760-1_23 Baratella, R., Fumagalli, M., Oliveira, Í., Guizzardi, G.: Understanding and modeling prevention. In: Guizzardi, R., Ralyte, J., Franch, X. (eds.) International Conference on Research Challenges in Information Science, LNBIP, vol. 446, pp. 389–405. Springer (2022). https://​doi.​org/​10.​1007/​978-3-031-05760-1_​23
3.
Zurück zum Zitat van den Bosch, S.: Designing Secure Enterprise Architectures A comprehensive approach: framework, method, and modelling language. Master’s thesis (2014) van den Bosch, S.: Designing Secure Enterprise Architectures A comprehensive approach: framework, method, and modelling language. Master’s thesis (2014)
4.
Zurück zum Zitat Guizzardi, G.: Ontological foundations for structural conceptual models (2005) Guizzardi, G.: Ontological foundations for structural conceptual models (2005)
5.
Zurück zum Zitat Guizzardi, G., et al.: Grounding software domain ontologies in the Unified Foundational Ontology (UFO): the case of the ODE software process ontology. In: Ibero-American Conference on Software Engineering, pp. 127–140 (2008) Guizzardi, G., et al.: Grounding software domain ontologies in the Unified Foundational Ontology (UFO): the case of the ODE software process ontology. In: Ibero-American Conference on Software Engineering, pp. 127–140 (2008)
6.
Zurück zum Zitat ISO: ISO 31000:2018 - Risk management - Guidelines (2018) ISO: ISO 31000:2018 - Risk management - Guidelines (2018)
7.
Zurück zum Zitat Lankhorst, M.: Enterprise Architecture at Work: Modelling, Communication and Analysis. Springer (2017) Lankhorst, M.: Enterprise Architecture at Work: Modelling, Communication and Analysis. Springer (2017)
8.
Zurück zum Zitat Mayer, N., Feltus, C.: Evaluation of the risk and security overlay of archimate to model information system security risks. In: 2017 IEEE 21st International Enterprise Distributed Object Computing Workshop (EDOCW), pp. 106–116. IEEE (2017) Mayer, N., Feltus, C.: Evaluation of the risk and security overlay of archimate to model information system security risks. In: 2017 IEEE 21st International Enterprise Distributed Object Computing Workshop (EDOCW), pp. 106–116. IEEE (2017)
12.
Zurück zum Zitat Sales, T.P., et al.: Ontological analysis and redesign of risk modeling in ArchiMate. In: Intl. Enterprise Distributed Object Computing Conference, pp. 154–163 (2018) Sales, T.P., et al.: Ontological analysis and redesign of risk modeling in ArchiMate. In: Intl. Enterprise Distributed Object Computing Conference, pp. 154–163 (2018)
14.
Zurück zum Zitat Teixeira, J.M.L.: Modelling Risk Management using ArchiMate. Master’s thesis (2017) Teixeira, J.M.L.: Modelling Risk Management using ArchiMate. Master’s thesis (2017)
Metadaten
Titel
Ontological Analysis and Redesign of Security Modeling in ArchiMate
verfasst von
Ítalo Oliveira
Tiago Prince Sales
João Paulo A. Almeida
Riccardo Baratella
Mattia Fumagalli
Giancarlo Guizzardi
Copyright-Jahr
2022
DOI
https://doi.org/10.1007/978-3-031-21488-2_6

Premium Partner