DocumentCode :
2709194
Title :
Enterprise Assets Security Requirements Construction from ESRMG Grammar based on Security Patterns
Author :
Supaporn, Kawin ; Prompoon, Nakornthip ; Rojkangsadan, Thongchai
Author_Institution :
Chulalongkorn Univ., Bangkok
fYear :
2007
fDate :
4-7 Dec. 2007
Firstpage :
112
Lastpage :
119
Abstract :
One of the highest priorities of system requirements needed in software development industry is security requirements. However, to identify the complete and correct software security requirements are a challenging task especially creating enterprise assets security requirements. Enterprise assets security requirements are to identify security basic needs, to assess risks, to establish security approach and service, and to specify external enterprise consideration including confidentiality, integrity, availability, and accountability concerns. Moreover, these may be applied to other security requirements such as identification and authentication, access control, firewall architecture, etc. Security patterns may be used to create this security requirements but understanding, analyzing and transforming from security patterns to security requirements are difficult to accomplish. We proposed a grammar, called ESRMG (enterprise security and risk management grammar), and a prototyping tool based on security patterns in a scope of enterprise asset identification and risk managements which are the fundamental of enterprise security requirements. The proposed grammar and tool are beneficial for any organization to construct enterprise security requirements and may help reduce cost and time in overall of system development.
Keywords :
business data processing; risk management; security of data; software engineering; ESRMG grammar; enterprise assets security requirements construction; enterprise security and risk management grammar; security patterns; software development industry; software security; system requirements; Access control; Authentication; Availability; Computer industry; Construction industry; Pattern analysis; Programming; Prototypes; Risk management; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Engineering Conference, 2007. APSEC 2007. 14th Asia-Pacific
Conference_Location :
Aichi
ISSN :
1530-1362
Print_ISBN :
0-7695-3057-5
Type :
conf
DOI :
10.1109/ASPEC.2007.53
Filename :
4425844
Link To Document :
بازگشت