Towards a framework for security in eScience

This paper describes an approach to the formulation and classification of security requirements in eScience. It explains why it is untenable to suggest that 'one size fits all', and that what is an appropriate security solution in one context may not be at all appropriate in another. It pr...

Descrición completa

Detalles Bibliográficos
Main Authors: Martin, A, Davies, J, Harris, S
Formato: Journal article
Idioma:English
Publicado: 2010
_version_ 1826275035424227328
author Martin, A
Davies, J
Harris, S
author_facet Martin, A
Davies, J
Harris, S
author_sort Martin, A
collection OXFORD
description This paper describes an approach to the formulation and classification of security requirements in eScience. It explains why it is untenable to suggest that 'one size fits all', and that what is an appropriate security solution in one context may not be at all appropriate in another. It proposes a framework for the description of eScience security in a number of different dimensions, in terms of measures taken and controls achieved. A distinctive feature of the framework is that these descriptions are organised into a set of discrete criteria, in most cases presented as levels of increasing assurance. The intended framework should serve as a basis for the systematic analysis of security solutions, facilitating the processes of design and approval, as well as for the identification of expectations and best practice in particular domains. The possible usage of the framework, and the value of the approach, is demonstrated in the paper through application to the design of a national data sharing service. © 2010 IEEE.
first_indexed 2024-03-06T22:52:34Z
format Journal article
id oxford-uuid:5f4a962e-6362-40db-ae59-ab5a363e5d73
institution University of Oxford
language English
last_indexed 2024-03-06T22:52:34Z
publishDate 2010
record_format dspace
spelling oxford-uuid:5f4a962e-6362-40db-ae59-ab5a363e5d732022-03-26T17:45:58ZTowards a framework for security in eScienceJournal articlehttp://purl.org/coar/resource_type/c_dcae04bcuuid:5f4a962e-6362-40db-ae59-ab5a363e5d73EnglishSymplectic Elements at Oxford2010Martin, ADavies, JHarris, SThis paper describes an approach to the formulation and classification of security requirements in eScience. It explains why it is untenable to suggest that 'one size fits all', and that what is an appropriate security solution in one context may not be at all appropriate in another. It proposes a framework for the description of eScience security in a number of different dimensions, in terms of measures taken and controls achieved. A distinctive feature of the framework is that these descriptions are organised into a set of discrete criteria, in most cases presented as levels of increasing assurance. The intended framework should serve as a basis for the systematic analysis of security solutions, facilitating the processes of design and approval, as well as for the identification of expectations and best practice in particular domains. The possible usage of the framework, and the value of the approach, is demonstrated in the paper through application to the design of a national data sharing service. © 2010 IEEE.
spellingShingle Martin, A
Davies, J
Harris, S
Towards a framework for security in eScience
title Towards a framework for security in eScience
title_full Towards a framework for security in eScience
title_fullStr Towards a framework for security in eScience
title_full_unstemmed Towards a framework for security in eScience
title_short Towards a framework for security in eScience
title_sort towards a framework for security in escience
work_keys_str_mv AT martina towardsaframeworkforsecurityinescience
AT daviesj towardsaframeworkforsecurityinescience
AT harriss towardsaframeworkforsecurityinescience