首页> 外文会议>Workshops on business informatics research >Security Requirements Engineering for Secure Business Processes
【24h】

Security Requirements Engineering for Secure Business Processes

机译:安全业务流程的安全需求工程

获取原文
获取原文并翻译 | 示例

摘要

Traditional approaches to business process modelling deal with security only after the business process has been denned, namely without considering security needs as input for the definition. This may require very costly corrections if new security issues are discovered. More over, security concerns are mainly considered at the system level without providing the rationale for their existence, that is, without taking into account the social or organizational perspective, which is essential for business processes related to considerably large organizations. In this pa per, we introduce a framework for engineering secure business processes. We propose a security requirements engineering approach to model and analyze participants' objectives and interactions, and then derive from them a set of security requirements that are used to annotate business processes. We capture security requirements through the notion of so cial commitment, that is a promise with contractual validity between participants. We illustrate the framework by means of an Air Traffic Management scenario.
机译:传统的业务流程建模方法仅在拒绝业务流程之后才处理安全性,即不考虑将安全需求作为定义的输入。如果发现新的安全问题,则可能需要进行非常昂贵的更正。此外,安全问题主要是在系统级别上考虑的,而没有提供其存在的理由,即,没有考虑社会或组织的观点,这对于与相当大的组织相关的业务流程至关重要。在本白皮书中,我们介绍了一种工程安全业务流程的框架。我们提出了一种安全需求工程方法来对参与者的目标和交互进行建模和分析,然后从中推导出一组用于注释业务流程的安全需求。我们通过社会承诺的概念来捕获安全性要求,这是参与者之间具有合同效力的承诺。我们通过空中交通管理场景来说明该框架。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号