首页> 外文会议>IEEE International Conference on Research Challenges in Information Science >Evaluation of MUSER, a holistic security requirements analysis framework
【24h】

Evaluation of MUSER, a holistic security requirements analysis framework

机译:评估MUSER,一个整体的安全需求分析框架

获取原文

摘要

Security has been a growing concern for large organizations, especially financial and governmental institutions, as security breaches in the systems they depend on have repeatedly resulted in billions of dollars in losses per year, and this cost is on the rise. A primary reason for these breaches is that the systems in question are socio-technical - a mix of people, processes, technology and infrastructure. However, such systems are designed in a piecemeal rather than a holistic fashion, leaving parts of the system vulnerable. To tackle this problem, a three-realm security requirements framework was proposed to holistically analyse security requirements in different conceptual realms, including social realm (business processes, social actors), a software realm (software applications that support the social realm) and an infrastructure realm (physical and technological infrastructure). In this paper we evaluate this security requirements analysis framework. The evaluation was performed by two graduate students using a large scale case study on a medical emergency response system.
机译:对于大型组织,尤其是金融和政府机构,安全性日益引起关注,因为它们所依赖的系统中的安全漏洞每年反复造成数十亿美元的损失,而且这种成本还在上升。造成这些破坏的主要原因是,所讨论的系统是社会技术的-人员,流程,技术和基础架构的组合。但是,这样的系统是零碎的而不是整体的设计,从而使系统的某些部分易受攻击。为了解决此问题,提出了一个三领域安全需求框架,以从整体上分析不同概念领域中的安全需求,这些概念领域包括社会领域(业务流程,社会参与者),软件领域(支持社会领域的软件应用程序)和基础架构领域(物理和技术基础结构)。在本文中,我们评估了此安全需求分析框架。评估是由两名研究生使用医疗事故应急系统的大规模案例研究进行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号