DocumentCode :
2416895
Title :
An Enterprise Level Security Requirements Specification Model
Author :
Anderson, Evan ; Choobineh, Joobin ; Grimaila, Michael R.
Author_Institution :
Texas A&M University; College Station, TX
fYear :
2005
fDate :
03-06 Jan. 2005
Abstract :
A formal model of security requirements for enterprise information technology protection is developed. The model is based on set theory and represented using an Entity-Relationship diagram. Components of the model include high level business objectives and their criticality, business requirements and their utilization, resources and their characterization as protector or protected resources, controls and their effectiveness, threats, vulnerabilities, potential exploits, and the resulting impact. An example representation of a formal relationship is provided. The model provides a canonical representation of enterprise security, enables automation and hence rigorous analysis of the security cost and effectiveness, provides for completeness and consistency checking, and offers a means for what-if as well as comparative analysis of security readiness.
Keywords :
Automatic control; Automation; Costs; Data security; Electronic mail; Information security; Information technology; Protection; Resource management; Set theory;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
System Sciences, 2005. HICSS '05. Proceedings of the 38th Annual Hawaii International Conference on
ISSN :
1530-1605
Print_ISBN :
0-7695-2268-8
Type :
conf
DOI :
10.1109/HICSS.2005.88
Filename :
1385614
Link To Document :
بازگشت