首页> 外文会议>Americas conference on information systems;AMCIS 2011 >Designing Security Requirements - A Flexible, Balanced,and Threshold-Based Approach
【24h】

Designing Security Requirements - A Flexible, Balanced,and Threshold-Based Approach

机译:设计安全要求-灵活,平衡且基于阈值的方法

获取原文

摘要

Defining security requirements is the important first step in designing, implementing and evaluating a secure system. In this paper, we propose a formal approach for designing security requirements, which is flexible for a user to express his/her security requirements with different levels of details and for the system developers to take different options to design and implement the system to satisfy the user's requirements. The proposed approach also allows the user to balance the required system security properties and some unfavorable features (e.g., performance degrading due to tight control and strong security). Given the importance of social-technical factors in information security, the proposed approach also incorporates economic and organizational security management factors in specifying user's security requirements. We demonstrate the application of our approach with the help of a concrete pervasive information system.
机译:定义安全要求是设计,实施和评估安全系统的重要第一步。在本文中,我们提出了一种用于设计安全需求的正式方法,该方法可以灵活地使用户用不同的详细程度来表达其安全需求,并且使系统开发人员可以采用不同的选项来设计和实现系统,以满足用户的需求。用户要求。所提出的方法还允许用户平衡所需的系统安全性和一些不利的功能(例如,由于严格控制和强大的安全性而导致的性能下降)。考虑到社会技术因素在信息安全中的重要性,建议的方法还将经济和组织安全管理因素纳入指定用户的安全要求中。我们将在一个具体的普适信息系统的帮助下演示我们方法的应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号