DocumentCode :
2865299
Title :
An Organization-Driven Approach for Enterprise Security Development and Management
Author :
Dai, Lirong ; Bai, Yan
Author_Institution :
Dept. of Comput. Sci. & Software Eng., Seattle Univ., Seattle, WA, USA
fYear :
2011
fDate :
27-29 June 2011
Firstpage :
208
Lastpage :
215
Abstract :
Enterprises security is a complex problem. Pure technology-driven development methods are not sufficient to solve a broad range of enterprise security issues. This paper analyzes the complexity of enterprise security and proposes an organization-driven approach for the problem. The approach combines a set of Unified Modeling Language-based approaches to bridge the gap between enterprise security architecture models and security application development models. It allows an enterprise to coordinate security resources from an enterprise point of view, and develop security applications systematically and efficiently. A comprehensive case study is conducted to illustrate the approach. The study shows through the refinement of enterprise security goals, both software goals and software requirements for a security application can be obtained. In particular, a security application is built to support the specification and automated verification of separation of duty access policies using the Object Constraint Language and formal method Alloy.
Keywords :
Unified Modeling Language; authorisation; business data processing; formal specification; formal verification; organisational aspects; duty access policy; enterprise security architecture model; enterprise security development; enterprise security management; formal specification; formal verification; object constraint language; organization-driven approach; security application development model; technology-driven development; unified modeling language-based approach; Access control; Business; Computer architecture; Object oriented modeling; Software; Unified modeling language; Access Control; Enterprise Security; Organization-Driven;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Secure Software Integration and Reliability Improvement (SSIRI), 2011 Fifth International Conference on
Conference_Location :
Jeju Island
Print_ISBN :
978-1-4577-0780-3
Electronic_ISBN :
978-0-7695-4453-3
Type :
conf
DOI :
10.1109/SSIRI.2011.25
Filename :
5992020
Link To Document :
بازگشت