首页> 外文会议>SpaceOps conference >Applying Secure Software Engineering (SSE) Practices to Critical Space System Infrastructure Development
【24h】

Applying Secure Software Engineering (SSE) Practices to Critical Space System Infrastructure Development

机译:将安全软件工程(SSE)实践应用于关键空间系统基础架构开发

获取原文
获取外文期刊封面目录资料

摘要

Spacecraft are assets of very high tangible and intangible value which embed, are operated and are controlled through a large number of software systems. These software systems play a critical role in the operation as well as timely service provision and data distribution for these assets. In Europe the ever increasing number of European Space Agency (ESA) Programmes, in particular those in which the European Union is involved with stringent security requirements, e.g. Galileo, Copernicus, Space Situational Awareness, impose higher consideration for secure software engineering than ever before. Therefore ensuring application security is becoming a mandatory requirement for ESA. Such an approach is essential for the benefit of current and future programmes and therefore should be embedded as an integral part of the software development lifecycle. In 2013, ESA started and Agency-internal activity on Secure Software Engineering (SSE) with the participation of several ESA directorates and projects. The main objective of this activity has been to standardise secure software engineering processes on top of existing European Cooperation for Space Standardisation (ECSS) software engineering and product assurance standards and to provide practical guidance to the ESA software engineering practitioners supporting effective and efficient implementation of these SSE practices and processes. The standard has been developed first internally for ESA but the plan is to evolve it to ECSS level. The main outputs of this activity are several documents: 1) A Secure Software Engineering Gap Analysis Technical Note that documents gaps found between the ECSS standards and secure software and systems engineering best practices; 2) An Internal Secure Software Engineering Standard that specifies and formalises secure software engineering processes on the basis of the ECSS E-40 and Q-80 software engineering standards; 3) An Internal Secure Software Engineering Handbook of guidelines for implementation of the standard; 4) A Glossary of Secure Software Engineering Terms; and 5) A Baseline Catalogue of Security Requirements that contains security requirements to be used during the security requirements specification process as defined in the standard. This paper provides a descriptive overview of the secure software engineering standard and also outline the supporting guidance available as part of the handbook and catalogue of security requirements.
机译:航天器是具有很高的有形和无形价值的资产,它们被嵌入,操作并通过大量软件系统进行控制。这些软件系统在这些资产的运营以及及时提供服务和数据分发中起着至关重要的作用。在欧洲,越来越多的欧洲航天局(ESA)计划,特别是那些涉及欧洲联盟等严格安全要求的计划。伽利略,哥白尼,太空态势感知,比以往任何时候都更加重视安全软件工程。因此,确保应用程序安全性已成为ESA的强制性要求。这种方法对于当前和将来的程序都是必不可少的,因此应作为软件开发生命周期的组成部分进行嵌入。 2013年,在多个ESA理事会和项目的参与下,ESA开始了安全软件工程(SSE)的机构内部活动。这项活动的主要目的是在现有的欧洲空间合作标准化组织(ECSS)软件工程和产品保证标准的基础上对安全软件工程流程进行标准化,并为ESA软件工程从业人员提供实践指导,以支持有效和高效地实施这些程序。上证所实践和流程。该标准最初是在内部为ESA开发的,但计划是将其发展到ECSS级别。该活动的主要输出是几个文档:1)安全软件工程差距分析技术说明,该文档记录了ECSS标准与安全软件和系统工程最佳实践之间的差距; 2)内部安全软件工程标准,该标准在ECSS E-40和Q-80软件工程标准的基础上指定和规范了安全软件工程流程; 3)《内部安全软件工程手册》中有关标准实施的指南; 4)安全软件工程术语表;和5)安全需求基准目录,其中包含要在标准中定义的安全需求规范过程中使用的安全需求。本文提供了安全软件工程标准的描述性概述,还概述了作为安全手册和目录的一部分可用的支持指南。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号