Title :
Toward the Engineering of Security of Information Systems (ESIS): UML and the IS Confidentiality
Author :
Goudalo, Wilson ; Seret, Dominique
Author_Institution :
Res. Center in Inf. of Paris CRIP5, Paris Descartes Univ., Paris
Abstract :
Managing the security of information systems (SIS) is at once a tedious task and the cornerstone of business in a highly competitive environment. Successful control of the SIS in a business requires many years of experience, expertise and continuous improvement. This implies real know-how for the employees who are responsible for SIS control. This article focuses on the encapsulation of this know-how into UML models through profiles according to the meta-object facility (MOF) standards from the object management group (OMG). The main idea is to understand, manipulate and exploit this delicate and valuable know-how without being necessarily an expert on SIS. This challenge is threefold: firstly, to find a common language, as well as approaches and tools for Engineering of both IS and SIS; secondly, to generate earnings and make use of the enormous progress in Engineering of IS, to establish and improve Engineering of SIS; and thirdly, to achieve homogeneous management and follow-up of IT projects and their security. This paper presents the context of the Engineering of Security of Information Systems, its importance and the feasibility of this challenge.
Keywords :
Unified Modeling Language; information systems; security of data; Engineering of Security of Information Systems; UMI models; confidentiality; meta-object facility standards; object management group; Application software; Engineering management; Information security; Information systems; Insurance; Management information systems; Object oriented modeling; Solid modeling; Systems engineering and theory; Unified modeling language; Engineering of Security; IS Confidentiality; Management of Security; Security of Information Systems; UML profiles;
Conference_Titel :
Emerging Security Information, Systems and Technologies, 2008. SECURWARE '08. Second International Conference on
Conference_Location :
Cap Esterel
Print_ISBN :
978-0-7695-3329-2
Electronic_ISBN :
978-0-7695-3329-2
DOI :
10.1109/SECURWARE.2008.66