Utilizing security requirements engineering methods for operational security maintenance purposes

被引:0
|
作者
Abuosba, Khalil
El-Sheikh, Asim
Martin, Clemens
机构
关键词
security; fault; event; trees; maintenance;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Secure systems are achieved by implementing appropriate controls and policies specified based on appropriate selection of minimum security requirements. Maintaining security for these systems is a major challenge. Systems may encounter threats that may arise due to exploitation of vulnerabilities or due to programming flaws. In this work we address security requirements engineering approaches and focus primarily on methods that may be utilized for the purpose of investigating incidents. We have shown empirically that threats may be identified by using methods such as faults trees; and systematically that by using other methods such as events trees, incidents may be avoided or prevented.
引用
收藏
页码:1763 / 1767
页数:5
相关论文
共 50 条
  • [31] Guest Editorial: Requirements Engineering for Information Security
    Annie I. Antón
    Requirements Engineering, 2002, 7 (4) : 177 - 178
  • [32] Security Requirements Engineering Process for Web Applications
    Salini, P.
    Kanmani, S.
    INTERNATIONAL CONFERENCE ON MODELLING OPTIMIZATION AND COMPUTING, 2012, 38 : 2799 - 2807
  • [33] Enhancing security requirements engineering by organizational learning
    Schneider, Kurt
    Knauss, Eric
    Houmb, Siv
    Islam, Shareeful
    Juerjens, Jan
    REQUIREMENTS ENGINEERING, 2012, 17 (01) : 35 - 56
  • [34] Security Engineering with AutomationML – A Methodology for Modeling Security Decisions, Goals, Risks, and Requirements
    Taştan E.
    Drath R.
    Fluchs S.
    VDI Berichte, 2023, 2023 (2419): : 413 - 428
  • [35] Characterization of Selected Security-related Standards in the Field of Security Requirements Engineering
    Fujs, Damjan
    Bernik, Igor
    ELEKTROTEHNISKI VESTNIK, 2022, 89 (03): : 73 - 80
  • [36] Characterization of Selected Security-related Standards in the Field of Security Requirements Engineering
    Fujs, Damjan
    Bernik, Igor
    Elektrotehniski Vestnik/Electrotechnical Review, 2022, 89 (03): : 73 - 80
  • [37] Model driven security engineering for the realization of dynamic security requirements in collaborative systems
    Alam, Muhammad
    MODELS IN SOFTWARE ENGINEERING, 2007, 4364 : 278 - 287
  • [39] Remote maintenance and OT security Requirements and implementation approaches
    Langreder, Philipp
    Hannover, Hochschule
    Schmidt, Frank
    Niemann, Karl-Heinz
    ATP MAGAZINE, 2022, (09): : 64 - 73
  • [40] A review on security requirements specification by formal methods
    Mishra, Aditya Dev
    Mustafa, Khurram
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2022, 34 (05):