Supporting Risk Assessment With The Systematic Identification, Merging, And Validation Of Security Goals

RISK ASSESSMENT AND RISK-DRIVEN QUALITY ASSURANCE, RISK 2016(2017)

引用 1|浏览3
暂无评分
摘要
Assessing security-related risks in software or systems engineering is a challenging task: often, a heterogeneous set of distributed stakeholders creates a complex system of (software) components which are highly connected to each other, consumer electronics, or Internetbased services. Changes during development are frequent and must be evaluated and handled efficiently. Consequently, risk assessment itself becomes a complex task and its results must be comprehensible by all actors in the distributed environment. Especially, systematic and repeatable identification of security goals based on a model of the system under development (SUD) is not well-supported in established methods. Thus, we demonstrate how the systematic identification, merging, and validation of security goals based on a model of the SUD in a concrete implementation of our method Modular Risk Assessment (MoRA) supports security engineers to handle this challenge.
更多
查看译文
关键词
Risk assessment, Security goals, Model-based, Security engineering, Method
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要