【24h】

Factors Related to the Implementation of ISSE: A Quality Perspective

机译:与ISSE实施相关的因素:质量观点

获取原文
获取原文并翻译 | 示例

摘要

'Bolting on' security functionality in Information Technology (IT) systems late in the System Development Life Cycle (SDLC) can be expensive and adversely affect system functionality and usability. Information Systems Security Engineering (ISSE) is a specialized application of systems engineering that addresses the identification of security requirements and their successful translation into IT system design. Yet experience has shown that security is often the "sacrificial lamb" when project managers seek to trade scope to meet cost and schedule requirements despite increasing security and privacy regulation in multiple industries. Given the proper application of ISSE would preclude such choices, overcoming barriers to implementation of ISSE in the SDLC would help project managers provide targeted application of scarce resources; facilitate proper security engineering; reduce overall risk to project scope, cost and schedule; and address the most critical IT security compliance issues affecting their project.
机译:在系统开发生命周期(SDLC)后期,信息技术(IT)系统中的“增强”安全功能可能很昂贵,并且会对系统功能和可用性产生不利影响。信息系统安全工程(ISSE)是系统工程的专用应用程序,可解决安全要求的识别及其成功转换为IT系统设计的问题。然而,经验表明,尽管在多个行业中提高了安全性和隐私权法规,但是当项目经理寻求交易范围以满足成本和进度要求时,安全性通常是“牺牲品”。鉴于ISSE的正确应用将排除此类选择,克服SDLC中实施ISSE的障碍将有助于项目经理针对稀缺资源提供有针对性的应用;促进适当的安全工程;降低项目范围,成本和进度的总体风险;并解决影响其项目的最关键的IT安全合规性问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号