We present the structure of an ontology for Information Security (IS) and discuss a paradigm whereby it can be used to extract knowledge from natural language texts such as IS standards, security policies and security control descriptions. Besides providing a vocabulary for the IS domain, the proposed ontology stores logical forms corresponding to statements in the text, as well as a set of axioms used for inference in description logic (DL). We also describe a tool to provide automatic support for the formalization process.
Citation:
Fernando N?ufel do Amaral, Carlos Baz?lio, Geiza Maria Hamazaki da Silva, Alexandre Rademaker, Edward Hermann Haeusler, "An Ontology-based Approach to the Formalization of Information Security Policies," edocw, pp.1, 10th IEEE International Enterprise Distributed Object Computing Conference Workshops (EDOCW'06), 2006