首页> 外文OA文献 >Adapting Secure Tropos for Security Risk Management during Early Phases of the Information Systems Development
【2h】

Adapting Secure Tropos for Security Risk Management during Early Phases of the Information Systems Development

机译:在信息系统开发的早期阶段调整安全Tropos以进行安全风险管理

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Security is a major target for today’s information systems (IS) designers. Security modelling languages exist to reason on security in the early phases of IS development, when the most crucial design decisions are made. Reasoning on security involves analysing risk, and effectively communicating risk-related information. However, we think that current languages can be improved in this respect. In this paper, we discuss this issue for Secure Tropos, the language supporting the eponymous agent-based IS development. We analyse it and suggest improvements in the light of an existing reference model for IS security risk management. This allows for checking Secure Tropos concepts and terminology against those of current risk management standards, thereby improving the conceptual appropriateness of the language. The paper follows a running example, called eSAP, located in the healthcare domain.
机译:安全是当今信息系统(IS)设计人员的主要目标。存在安全建模语言,可以在IS开发的早期阶段做出最关键的设计决策时就安全性进行推理。关于安全性的推理涉及分析风险,并有效地传达与风险相关的信息。但是,我们认为可以在这方面改进当前的语言。在本文中,我们将讨论Secure Tropos(支持同名基于代理的IS开发的语言)的问题。我们对其进行分析,并根据IS安全风险管理的现有参考模型提出改进建议。这样可以对照当前的风险管理标准检查Secure Tropos的概念和术语,从而提高该语言的概念适当性。本文遵循了一个位于医疗保健领域的正在运行的示例,称为eSAP。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号