首页> 外文会议>Global security, safety, and sustainability: Tomorrow's Challenges of Cyber Security >Towards a Common Security and Privacy Requirements Elicitation Methodology
【24h】

Towards a Common Security and Privacy Requirements Elicitation Methodology

机译:迈向通用安全和隐私要求启发方法

获取原文
获取原文并翻译 | 示例

摘要

There are many methodologies that have been proposed in the literature for identifying the security and privacy requirements that must be satisfied by an information system in order to protect its users. At the same time, there are several "privacy principles" that have been considered as equally important for the avoidance of privacy violation incidents. However, to the best of our knowledge, there is no methodology that can cover both the identification of the security and privacy requirements and at the same time to take into account the main privacy principles. The consequence is that the designers of an information system usually follow an ad hoc approach for the identification of security/privacy requirements, thus failing to protect users in an effective way. This paper introduces the main idea behind a methodology that integrates the basic steps of well-established risk analysis methodologies with those of methodologies used for the identification of privacy requirements, considering, at the same time, the most well-known privacy principles. The proposed methodology aims to assist information system designers to come up with a complete and accurate list of all security and privacy requirements that must be satisfied by the system.
机译:文献中已经提出了许多方法来识别信息系统必须满足的安全性和隐私要求,以保护其用户。同时,有几种“隐私原则”被认为对于避免侵犯隐私事件同样重要。但是,据我们所知,没有一种方法既可以涵盖安全性和隐私要求的识别,又可以同时考虑主要的隐私原则。结果是,信息系统的设计人员通常会采用临时方法来识别安全/隐私要求,从而无法有效地保护用户。本文介绍了一种方法论的主要思想,该方法论将既定的风险分析方法论的基本步骤与用于识别隐私要求的方法论相结合,同时考虑了最著名的隐私权原则。所提出的方法旨在帮助信息系统设计人员提出系统必须满足的所有安全和隐私要求的完整且准确的列表。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号