Enhancement of a Business Model with a Business Contextual Risk Model.

Zakariya Kamagaté,Jacques Simonin,Yvon Kermarrec

CRiSIS(2020)

引用 1|浏览0
暂无评分
摘要
In this paper, we propose an approach of security risk-driven contextual model for software systems development. The approach is model-driven using enterprise business architecture as the basis for the contextual models definition, associating security risk concerns. Enterprise Architecture (EA) enables the description of an organisation's structure, its business and its underlying Information System. By using a Model-Driven Engineering (MDE) approach such as Model-Driven Architecture (MDA), we dene an architecture for models, and we provide a set of guidelines for structuring specications expressed as (EA) contextual models. Then these models are enhanced to integrate security aspects in the overall development process. The proposal aims to analyse enterprise security from a business-oriented view and define security requirements inherited by the lower architectures, particularly IS architecture. The approach provides a meta-model of business contextual risk with a security management process, consisting on a systematic method, guiding to risk modelling and risk treatment strategies.
更多
查看译文
关键词
Risk,Models,Business scenario,Security,Threats,Software engineering,Enterprise architecture,Model-Driven Engineering,Model-driven architecture
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要