Title :
Requirements Management in a Combined Process for Safety and Security Assessments
Author :
Katta, Vikash ; Raspotnig, Christian ; Karpati, Peter ; Stalhane, Tor
Author_Institution :
Dept. Software Eng., Inst. for Energy Technol., Halden, Norway
Abstract :
Combined Harm Assessment of Safety and Security for Information Systems (CHASSIS) method defines a unified process for safety and security assessments to address both the safety and security aspects during system development process. CHASSIS applies techniques from safety and security fields-e.g. misuse case and HAZOP-to identify and model hazards, threats and mitigations to a system. These mitigations, which are generally specified as safety and security requirements, are interrelated. Defining and maintaining the interdependencies between these requirements are vital to, among other things, estimate how a requirement impacts other requirements and artefacts. In this paper, we present our approach for providing trace ability to CHASSIS in order to capture the interdependencies between the safety and security requirements and to demonstrate the history and rational behind their elicitation. The approach, called Satrap, constitutes a process model defining what type of artefacts are generated during development and assessment activities, what type of relations between the artefacts should be captured, and how to extract traces. The trace ability approach together with its supporting prototype tool was applied on an Air Traffic Management remote tower example which was assessed for safety and security risks using CHASSIS.
Keywords :
air traffic control; formal specification; risk management; security of data; traffic information systems; CHASSIS; SaTrAp; air traffic management remote tower; assessment activities; combined harm assessment of safety and security for information system method; development activities; process model; safety assessments; safety requirements management; safety risk; security assessments; security requirements management; security risk; traceability; traceability approach; Atmospheric modeling; Context; Hazards; Poles and towers; Security; Unified modeling language; ATM; UML; safety; security; traceability;
Conference_Titel :
Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
Conference_Location :
Regensburg
DOI :
10.1109/ARES.2013.104