DocumentCode
2865299
Title
An Organization-Driven Approach for Enterprise Security Development and Management
Author
Dai, Lirong ; Bai, Yan
Author_Institution
Dept. of Comput. Sci. & Software Eng., Seattle Univ., Seattle, WA, USA
fYear
2011
fDate
27-29 June 2011
Firstpage
208
Lastpage
215
Abstract
Enterprises security is a complex problem. Pure technology-driven development methods are not sufficient to solve a broad range of enterprise security issues. This paper analyzes the complexity of enterprise security and proposes an organization-driven approach for the problem. The approach combines a set of Unified Modeling Language-based approaches to bridge the gap between enterprise security architecture models and security application development models. It allows an enterprise to coordinate security resources from an enterprise point of view, and develop security applications systematically and efficiently. A comprehensive case study is conducted to illustrate the approach. The study shows through the refinement of enterprise security goals, both software goals and software requirements for a security application can be obtained. In particular, a security application is built to support the specification and automated verification of separation of duty access policies using the Object Constraint Language and formal method Alloy.
Keywords
Unified Modeling Language; authorisation; business data processing; formal specification; formal verification; organisational aspects; duty access policy; enterprise security architecture model; enterprise security development; enterprise security management; formal specification; formal verification; object constraint language; organization-driven approach; security application development model; technology-driven development; unified modeling language-based approach; Access control; Business; Computer architecture; Object oriented modeling; Software; Unified modeling language; Access Control; Enterprise Security; Organization-Driven;
fLanguage
English
Publisher
ieee
Conference_Titel
Secure Software Integration and Reliability Improvement (SSIRI), 2011 Fifth International Conference on
Conference_Location
Jeju Island
Print_ISBN
978-1-4577-0780-3
Electronic_ISBN
978-0-7695-4453-3
Type
conf
DOI
10.1109/SSIRI.2011.25
Filename
5992020
Link To Document