Title :
An Organization-Driven Approach for Enterprise Security Development and Management
Author :
Dai, Lirong ; Bai, Yan
Author_Institution :
Dept. of Comput. Sci. & Software Eng., Seattle Univ., Seattle, WA, USA
Abstract :
Enterprises security is a complex problem. Pure technology-driven development methods are not sufficient to solve a broad range of enterprise security issues. This paper analyzes the complexity of enterprise security and proposes an organization-driven approach for the problem. The approach combines a set of Unified Modeling Language-based approaches to bridge the gap between enterprise security architecture models and security application development models. It allows an enterprise to coordinate security resources from an enterprise point of view, and develop security applications systematically and efficiently. A comprehensive case study is conducted to illustrate the approach. The study shows through the refinement of enterprise security goals, both software goals and software requirements for a security application can be obtained. In particular, a security application is built to support the specification and automated verification of separation of duty access policies using the Object Constraint Language and formal method Alloy.
Keywords :
Unified Modeling Language; authorisation; business data processing; formal specification; formal verification; organisational aspects; duty access policy; enterprise security architecture model; enterprise security development; enterprise security management; formal specification; formal verification; object constraint language; organization-driven approach; security application development model; technology-driven development; unified modeling language-based approach; Access control; Business; Computer architecture; Object oriented modeling; Software; Unified modeling language; Access Control; Enterprise Security; Organization-Driven;
Conference_Titel :
Secure Software Integration and Reliability Improvement (SSIRI), 2011 Fifth International Conference on
Conference_Location :
Jeju Island
Print_ISBN :
978-1-4577-0780-3
Electronic_ISBN :
978-0-7695-4453-3
DOI :
10.1109/SSIRI.2011.25