Embedding policy rules for software-based systems in a requirements context

被引:1
|
作者
Strembeck, M [1 ]
机构
[1] Vienna Univ Econ & BA, New Media Lab, Dept Informat Syst, Vienna, Austria
关键词
D O I
10.1109/POLICY.2005.14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Policy rules define what behavior is desired in a software-based system, they do not describe the corresponding action and event sequences that actually "produce" desired ("legal") or undesired ("illegal") behavior Therefore, policy rules alone are not sufficient to model every (behavioral) aspect of an information system. In other words, like requirements policies only exist in context, and a policy rule set can only be assessed and sensibly interpreted with adequate knowledge of its embedding context. Scenarios and goals are artifacts used in requirements engineering and system design to model different facets of software systems. With respect to policy rules, scenarios are well suited to define how these rules are embedded into a specific environment. A goal is an objective that the system under consideration should or must achieve. Thus, the control objectives of a system must be reflected in the policy rules that actually govern a system's behavior.
引用
收藏
页码:235 / 238
页数:4
相关论文
共 50 条