Defining the minimum security baseline in a multiple security standards environment by graph theory techniques

Date
2019Author
Olifer, Dmitrij
Goranin, Nikolaj
Čenys, Antanas
Kačeniauskas, Arnas
Janulevičius, Justinas
Metadata
Show full item recordAbstract
One of the best ways to protect an organization’s assets is to implement security requirements defined by different standards or best practices. However, such an approach is complicated and requires specific skills and knowledge. In case an organization applies multiple security standards, several problems can arise related to overlapping or conflicting security requirements, increased expenses on security requirement implementation, and convenience of security requirement monitoring. To solve these issues, we propose using graph theory techniques. Graphs allow the presentation of security requirements of a standard as graph vertexes and edges between vertexes, and would show the relations between different requirements. A vertex cover algorithm is proposed for minimum security requirement identification, while graph isomorphism is proposed for comparing existing organization controls against a set of minimum requirements identified in the previous step.
