首页> 外文OA文献 >Using Common Criteria Methodology to Express Informal Security Requirements
【2h】

Using Common Criteria Methodology to Express Informal Security Requirements

机译:使用通用标准方法表达非正式安全要求

摘要

Often, security requirements for complex systems are hard to discern because it is difficult to determine which requirements must be allocated to the system and which pertain to the system environment. In the Common Criteria framework, threat analysis results in a set of objectives that can be subdivided into two major categories: those allocated to the system itself, and the remainder to the environment. By differentiating between these two types of objectives, it is possible to avoid inappropriate requirements specification. Moving beyond systems intended to undergo evaluation; we show that the Common Criteria methodology is effective in requirements analysis for informally specified systems. As a demonstration, a worked example using a Common Criteria-based process for a requirements analysis of an on-line dissemination system is presented.
机译:通常,很难确定复杂系统的安全要求,因为很难确定哪些要求必须分配给系统以及哪些要求与系统环境有关。在“通用标准”框架中,威胁分析产生了一组目标,这些目标可以分为两大类:分配给系统本身的目标,以及分配给环境的其余目标。通过区分这两种类型的目标,可以避免不合适的需求说明。超越旨在进行评估的系统;我们证明了通用标准方法在非正式指定系统的需求分析中是有效的。作为演示,提供了一个使用基于通用标准的过程进行在线分发系统需求分析的工作示例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号