ICST Conference icst

ISGIG 2008

First International Symposium on Global Information Governance 2008

March 13 - 14, 2008, Pisa, Italy

Aljosa Pasic

Aljosa Pasic
Head of AIM department, Atos Research & Innovation


The "security-aware" era, in which the belief that security must be a forethought and "built-in" component has gained popularity over the last few years. Although this belief acknowledges the need for integrating security into the early design and development phases of information systems, in practice, this integration has not yet been achieved. In current system development processes, security requirements are identified independently for each system component, such as network layer, server storage and computing resources, processing of sensitive data etc without explicitly considering the interdependences between them. In addition, these requirements are often limited just for a single context (user, environment, community etc), which for the future service oriented world seems inappropriate. NESSI working group on Trust, Security and Dependability (TSD) we have witnessed a growing interest in security information governance in service oriented systems. We envisage that securing the architecture will therefore be a part of global information governance process (as is the case of a proper security strategy) that needs to encompass requirements from various types of architecture properties and different stakeholders.