【24h】

Building security requirements with CLASP

机译:使用CLASP建立安全性要求

获取原文
获取原文并翻译 | 示例

摘要

Traditionally, security requirements have been derived in an ad hoc manner. Recently, commercial software development organizations have been looking for ways to produce effective security requirements.In this paper, we show how to build security requirements in a structured manner that is conducive to iterative refinement and, if followed properly, metrics for evaluation. While requirements specification cannot be a complete science, we provide a framework that is an obvious improvement over traditional methods that do not consider security at all.We provide an example using a simple three-tiered architecture. The methodology we document is a subset of CLASP, a set of process pieces for application security that we have recently published, in conjunction with IBM/Rational.
机译:传统上,安全要求是通过 ad hoc 方式得出的。最近,商业软件开发组织一直在寻找产生有效安全需求的方法。在本文中,我们展示了如何以结构化方式构建安全需求,这有利于迭代细化,并且如果正确遵循,还可以进行评估。虽然需求规范不是一门完整的科学,但我们提供了一个框架,该框架比根本不考虑安全性的传统方法有了明显的改进。我们提供了一个使用简单三层体系结构的示例。我们记录的方法是CLASP的子集,CLASP是我们最近与IBM / Rational联合发布的一组用于应用程序安全的过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号