Advanced Program

IFIP 11.1 & 11.5 Joint Working Conference, Fairfax, Virginia

December 1, 2005: Student Union II building, Room 3&4
Fairfax Campus, GMU




Session 1 - Security Standards Paul Dowland (Chair)
9:00 9:30 Information Security Standards: Adoption Drivers - What drives organisations to seek accreditation? the case of BS 7799-2:2002 (Invited paper) Jean-Noel Ezingeard and David Birchall
9:30 10:00 Data Quality Dimension for Information Systems Security: A Theoretical Exposition (Invited paper) Gurvirender Tejay, Gurpreet Dhillon and Amita Goyal Chin
10:00 10:30 From XML to RDF: Syntax, Semantics, Security and Integrity (Invited paper) C. Farkas, V. Gowadia, A. Jain, and D. Roy
10:30 11:00 Coffee Break




Session 2 - Security Culture Steve Furnell (Chair)
11:00 11:30 How much should we pay for security? (Invited paper) Sokratis K. Katsikas, Athanasios N. Yannacopoulos, Stefanos Gritzalis, Costas Lambrinoudakis and Peter Hatzopoulos
11:30 12:00 Don't Ship (or Receive) Trojan Horses Corey Hirsch
12:00 12:30 Employee Perceptions In Instilling Information Security Culture Omar Zakaria




12:30 14:00 Lunch Break: 


Student Union II building, Room 1&2 Fairfax Campus, GMU




Session 3 - Access Management Sean Wang (Chair)
14:00 14:30 A Policy Framework for Access Management in Federated Information Sharing Rafae Bhatti, Elisa Bertino, Arif Ghafoor
14:30 15:00 A Hierarchical Release Control Policy Framework Chao Yao; William H. Winsborough; Sushil Jajodia
15:00 15:30 Scalable Access Policy Administration:  Opinions and a Research Agenda (Invited paper) Arnon Rosenthal
15:30
16:00
Coffee Break





Session 4 - Risk Management Csilla Farkas (Chair)
16:00 16:30 Managing Uncertainty in Security Risk Model Forecasts with RAPSA/MC James R. Conrad and Paul Oman and Carol Taylor
16:30 17:00 Ensuring ICT Risks Using EMitL Tool: An Empirical Study Jabiri Kuwe Bakari, Charles N. Tarimo, Louise Yngström, Christer Magnusson
17:00 17:30 Risk Communication, Risk Perception and Information Security Malcolm Pattinson, Grantley Anderson
17:30 18:00 A Holistic Risk Analysis Method for Identifying Information Security Risks Janine L. Spears




December 2, 2005: Johnson Center Room C
Fairfax Campus, GMU




Session 5 - Security Culture Sokratis Katsikas (Chair)
9:00 9:30 A Responsibility Framework for Information Security S Posthumus and R von Solms
9:30 10:00 Information Security Governance - A Re-definition Rahul Rastogi and R von Solms
10:00 10:30 Can we tune Information Security Management into meeting Corporate Governance needs? (Invited paper) Louise Yngström




10:30 11:00 Coffee Break




Session 6 - Security Management Rossouw von Solms (Chair)
11:00 11:30 Measurement of Information Security in Processes and Products Reijo Savola, Juhani Anttila, Anni Sademies, Jorma Kajava, Jarkko Holappa
11:30 12:00 A protection-profiles approach to risk analysis for small and medium enterprises Vassilis Dimopoulos, Steven Furnell
12:00 12:30 A UML approach in the ISMS implementation Andrzej Białas




12:30 14:00 Lunch Break: Johnson Center Room D





Session 7 - Applications Paul Thompson (Chair)
14:00 14:30 Attack Aware Integrity Control in Databases (Invited paper)  Peng Liu
14:30 15:00 Characteristics and measures for mobile-masquerader detection Oleksiy Mazhelis, Seppo Puuronen
15:00 15:30 A Distributed Service Registry for Resource Sharing among Ad-hoc Dynamic Coalitions (Invited paper) Ravi Mukkamala, Vijayalakshmi Atluri




15:30 16:00 Coffee Break




Session 8 - Access Management Peng Liu (Chair)
16:00 16:30 A Policy-Oriented Trust-Based Decision Model and a Policy Language for Information Integrity in Open Systems Yanjun Zuo and Brajendra Panda
16:30 17:00 Semantic Information Infrastructure Protection (Invited paper) Paul Thompson




End of Conference