Title :
ISEDS: An Information Security Engineering Database System Based on ISO Standards
Author :
Horie, Daisuke ; Morimoto, Shoichi ; Azimah, Noor ; Goto, Yuichi ; Cheng, Jingde
Author_Institution :
Dept. of Inf. & Comput. Sci., Saitama Univ., Saitama
Abstract :
Security facilities of information systems with high security requirements should be consistently and continuously developed, used, and maintained based on some common standards of information security. However, there is no engineering environment that can support all tasks in security engineering consistently and continuously. To construct a security engineering environment, a database that can manage all data concerning all tasks in security engineering is indispensable. This paper presents an Information Security Engineering Database System, named "ISEDS," that we are developing based on ISO standards, and shows its some possible applications. ISEDS manages data of ISO standards of information security and various cases of system development and maintenance. We adopted the international standard ISO/IEC 15408 (Common Criteria) for information security evaluation as one of ISO standards to underlie ISEDS, and implemented major functions of ISEDS and its application tools to manage and use data oflSO/IEC 15408. Developers, users, and maintainers can create, correct, and verify specification documents of security facilities with the application tools.
Keywords :
IEC standards; ISO standards; database management systems; security of data; ISO standards; ISO/IEC 15408; information security engineering database system; information security evaluation; information systems; security facilities; system development; system maintenance; Data engineering; Data security; Database systems; IEC standards; ISO standards; Information security; Maintenance engineering; Management information systems; Standards development; Systems engineering and theory; An Information Security Engineering Database System; Common Criteria; ISO/IEC 15408; Information security; Supporting design of security facilities; Supporting maintenance of security facilities;
Conference_Titel :
Availability, Reliability and Security, 2008. ARES 08. Third International Conference on
Conference_Location :
Barcelona
Print_ISBN :
978-0-7695-3102-1
DOI :
10.1109/ARES.2008.76