DocumentCode
2222822
Title
Integrating information security engineering with system engineering with system engineering tools
Author
Higginbotham, M. Douglas ; Milheizler, Albert J. ; Maley, Joseph G. ; Suskie, Bernard J.
Author_Institution
Booz-Allen & Hamilton, USA
fYear
1998
fDate
17-19 Jun 1998
Firstpage
320
Lastpage
326
Abstract
Users of automated information systems (AISs) are becoming increasingly aware of the inherent risks associated with placing sensitive information on a system. Users are beginning to demand an assessment of the quality of security services offered because they need to make informed decisions on accepting certain levels of risk associated with protecting information they place on a system. By integrating an information system security engineering (ISSE) process into system development or system enhancement activities, system developers can satisfy user concerns. An ISSE process will identify the quality of security services needed by users; help identify security mechanisms to satisfy user needs; lead to an effective security design; identify the quality of security services offered by the actual system; and develop the documentation necessary to effectively market the security services offered by a system. An effective and cost efficient method for managing and providing discipline for the ISSE process is for system developers to use an automated system engineering tool. Such a tool significantly enhances the system security engineering team´s ability to satisfy user security needs throughout the system design process
Keywords
information systems; security of data; system documentation; systems engineering; automated information systems; automated system engineering tool; documentation; information protection; information security engineering; information system security engineering; informed decision making; risks; security service quality assessment; sensitive information; system development activities; system engineering; system enhancement activities; user concerns; user needs; Cost function; Design engineering; Documentation; Electronic switching systems; Engineering management; Information security; Process design; Protection; Systems engineering and theory;
fLanguage
English
Publisher
ieee
Conference_Titel
Enabling Technologies: Infrastructure for Collaborative Enterprises, 1998. (WET ICE '98) Proceedings., Seventh IEEE International Workshops on
Conference_Location
Stanford, CA
Print_ISBN
0-8186-8751-7
Type
conf
DOI
10.1109/ENABL.1998.725712
Filename
725712
Link To Document