Skip to main content

Routine – day-to-day security management using ESARIS

  • Chapter
  • First Online:
Book cover Secure ICT Service Provisioning for Cloud, Mobile and Beyond

Part of the book series: Edition <kes> ((EDKES))

  • 472 Accesses

Abstract

Larger IT departments and specialized ICT Service Providers must be able to define, communicate and correctly apply hundreds and thousands of single security measures in a large-scale, industrial environment with thousands of employees located in many countries. The IT production is characterized by standardization and a rigorous division of labor within the ICT Service Provider and its supplier network. The ICT Service Provider offers its ICT services to many customers (user organizations). There are new challenges with respect to IT security in such an environment. The Enterprise Security Architecture for Reliable ICT Services (ESARIS) is built to meet these challenges. This chapter investigates and summarizes effects on the security management. Essential tasks for the Security Management organization are highlighted. First, the focus is on differences at the provider’s side caused by meeting the new challenges by using ESARIS (Sect. 13.1). The actual implementation of the concepts and methods defined in ESARIS is a pre-condition for reaping the benefits of ESARIS, primarily higher efficiency and improved security. A primary task of the Security Management organization in day-to-day business is therefore to ensure that the company adheres to the security standards. There are different techniques for verifying if and to what extent security standards are actually applied (Sect. 13.2). The use of ESARIS decreases the effort for managing security but the Security Management organization of the ICT Service Provider will still have trouble and see confusion. A considerable portion of the security management activities must therefore be dedicated to motivation, cultural change, convincing, training and the like. Some important tips are provided to deal with trouble and confusion (Sect. 13.3). The security management of a user organization undergoes a big change when ICT services are outsourced for the first time. The last section focuses on major activities for the user organization’s Security Management organization. Together with the huge amount of detail about the provider’s side given in other chapters of this book, a portrait of a joint security management is drawn (Sect. 13.4).

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Eberhard von Faber .

Rights and permissions

Reprints and permissions

Copyright information

© 2017 Springer Fachmedien Wiesbaden GmbH

About this chapter

Cite this chapter

von Faber, E., Behnsen, W. (2017). Routine – day-to-day security management using ESARIS. In: Secure ICT Service Provisioning for Cloud, Mobile and Beyond. Edition <kes>. Springer Vieweg, Wiesbaden. https://doi.org/10.1007/978-3-658-16482-9_13

Download citation

  • DOI: https://doi.org/10.1007/978-3-658-16482-9_13

  • Published:

  • Publisher Name: Springer Vieweg, Wiesbaden

  • Print ISBN: 978-3-658-16481-2

  • Online ISBN: 978-3-658-16482-9

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics