The three articles in this special issue focus on the impact of mobile wireless communications networks (xG) on Information Technology and Systems. The “x” in xG is an expression of the rapid and impactful growth of mobile wireless communications networks. These generational increments are more than simply increasing network speed and connecting more devices. Each network generation in cellular and wireless communications has its own uniqueness that deserves rigorous and focused studies. This need is so because xG heralds an era of far- and wide-ranging services, applications, and systems that promise to change business, society, and government.
The rapid and worldwide spread of the coronavirus and its illness known as COVID-19 has made huge impact on almost everything has taken us all by surprise. We all are now experiencing a major unprecedented and unexpected global public health crisis. This pandemic has also triggered huge social upheavals, disrupted almost every industry, and impacted the life and work of everyone in almost every country. Businesses and educational institutions are closed, many employees are forced to work from their homes, supply chains have been disturbed, people are being required to self-isolate, and most travel, in-person meetings, and conventions have been banned. These disruptions could continue for months, and the resulting economic, business, and social impact will last for years.
The four articles in this special issue focus on communications recovery and resilience. Communications recovery and resiliency is a topic of great concern in current times as disasters have taken a greater toll on society. The current COVID-19 pandemic has made us more dependent on communications networks and this has increased the premium placed on technologies and its operations. Communications networks must be resilient, in support of various technologies during business disruptions, disaster recovery, and pandemic events. Recovery and resilience are two sides worth exploring here: 1) the needs and challenges with recovering from disasters of all types, and 2) how to enhance the resiliency of communication networks to provide better support in these difficult operations.
Conducting a risk assessment (RA) for cloud computing platforms presents new challenges in the space of Information Security Management Systems (ISMS). ISO 27001 RA methods have been used for Alcohol Monitoring Systems (AMS) across a portfolio of products and services. Scaling these localized techniques to national and international cloud security standards shows that a 'one size fits all' RA approach does not exist in the industry today. The context and methods for conducting cloud RA are examined across representative national and international standards and guidelines.
Risk assessment (RA) use cases for cloud computing platforms are presented in the context of an ISO 27001 Information Security Management System (ISMS) developed for Alcohol Monitoring Systems (AMS) across a portfolio of products and services.
The author presents six principles to help avoid bad security metrics problems and move forward using sound measurement. This is the second part of a two-part series.
Successfully addressing the cybersecurity needs of new technologies is not an easy task, but advances in data analytics, forensics, threat modeling, and other techniques presented in this special issue on Cyberthreats and Security can help us meet the challenge.
The RA approach of this paper is provided as a "tool in the toolbelt" in the process of obtaining ISO 27001 certification for cloud -based applications. The methods and techniques of this paper were conducted over a three-month period and have been peer reviewed at the recent Certified Infosec Conference 2018 (http://certinfosec.org) attended by an international group of compliance and audit profe...
This article presents a condensed account of the 10-year effort to develop and deploy vehicular public-key infrastructure (VPKI) as a security infrastructure for vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) intelligent transportations systems (ITS). The author discusses the ways in which government, industry, and academia have converged to bring the promise of vehicular networks as ITS into the reality of the 21st century.
The IEEE Computer Societys 28th Software Technology Conference (STC) brought together software practitioners from industry, government, and academia. The author highlights tracks, tutorials, and keynote presentations from the conference, which ranged from software cybersecurity, systems engineering, metrics, agile, test and verification, program management, the Internet of Things (IoT), and cloud computing.
This article presents a condensed account of the 10-year effort to develop and deploy vehicular public-key infrastructure (VPKI) as a security infrastructure for vehicle-to-vehicle (V2V) and vehicl...
How can IT professionals adapt to ever-changing security challenges quickly and without draining their organizations' resources? Articles in this issue highlight emerging trends and suggest ways to approach and address cybersecurity challenges.
This article provides insights and recommendations on designing and implementing converged physical and logical access control systems. Existing standards and models, either without modification or with clarifying enhancements, are available to assist in this effort. The PSIA Physical-Logical Access Interoperability (PLAI) specification combines the enhanced features of physical security, role-based AC, and attribute-based AC to provide facilities management "behind closed doors".
Is it possible to obtain the flexibility and advantages of attribute-based access control while maintaining role-based access control's advantages for analysis and risk control?
Most of today's large firms use some form of role-based access control (RBAC) to support thousands of users and permission controls. Recognizing the need for some commonality among the various RBAC models, the National Institute of Standards and Technology proposed the NIST Model for RBAC in 2000. NIST is now working to update and enhance this standard.
Vehicular networking has significant potential to enable diverse applications associated with traffic safety, traffic efficiency and infotainment. In this survey and tutorial paper we introduce the basic characteristics of vehicular networks, provide an overview of applications and associated requirements, along with challenges and their proposed solutions. In addition, we provide an overview of the current and past major ITS programs and projects in the USA, Japan and Europe. Moreover, vehicular networking architectures and protocol suites employed in such programs and projects in USA, Japan and Europe are discussed.
Merging the best features of RBAC and attribute-based systems can provide effective access control for distributed and rapidly changing applications.
Automotive networking on US highways is moving into high gear. Smart cars, connected vehicles, intelligent transportation systems (ITS), vehicular ad-hoc networks (VANET), and vehicle telematics represent parallel and overlapping technologies and services that will define the future of the American roadway systems'. The integration of computing technology and expanding communication services is driving the growing research and development efforts to integrate vehicles and roadway telematic services to improve preventive vehicle safety, reduce traffic congestion, and enable new applications for vehicle maintenance and commercial services. Industrial and governmental efforts are underway to accelerate the introduction of vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communications functions. In the United States these major ITS projects have included US DOT IntelliDrive, CAMP/VSC-2; SafeTrip21, IEEE WAVE, California PATH, and the Connected Vehicle Proving Center (CVPC).An Intelligent Transportation System (ITS) technical architecture for Service Management has been developed based on IEEE 1609 Wireless Access for Vehicular Environments (WAVE) standards for secure vehicle-to-vehicle and vehicle-to-infrastructure wireless communication. This study defines an ITS Service Management model based on the networking (IEEE 1609.3), and security (IEEE 1609.2) protocols. An examination of the working model demonstrates the use of a 1609.3 Provider Service Identifier (PSID) to provision and secure ITS services and applications using the DSRC/WAVE communication stack.
David W. Flater合作论文数U.S. Department of Commerce1