Security Requirements Engineering for Secure Business Processes

被引:0
作者
Paja, Elda [1 ]
Giorgini, Paolo [1 ]
Paul, Stephane [2 ]
Meland, Per Hakon [3 ]
机构
[1] Univ Trent, I-38100 Trento, Italy
[2] Thales Res & Technol, Palaiseau, France
[3] SINTEF, Trondheim, Norway
来源
WORKSHOPS ON BUSINESS INFORMATICS RESEARCH | 2012年 / 106卷
基金
欧盟第七框架计划;
关键词
Security requirements; business process; BPMN; social commitments;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Traditional approaches to business process modelling deal with security only after the business process has been defined, namely without considering security needs as input for the definition. This may require very costly corrections if new security issues are discovered. Moreover, security concerns are mainly considered at the system level without providing the rationale for their existence, that is, without taking into account the social or organizational perspective, which is essential for business processes related to considerably large organizations. In this paper, we introduce a framework for engineering secure business processes. We propose a security requirements engineering approach to model and analyze participants' objectives and interactions, and then derive from them a set of security requirements that are used to annotate business processes. We capture security requirements through the notion of social commitment, that is a promise with contractual validity between participants. We illustrate the framework by means of an Air Traffic Management scenario.
引用
收藏
页码:77 / +
页数:2
相关论文
共 19 条
  • [1] Business process modelling:: Review and framework
    Aguilar-Savén, RS
    [J]. INTERNATIONAL JOURNAL OF PRODUCTION ECONOMICS, 2004, 90 (02) : 129 - 149
  • [2] Allweyer T., 2010, BPMN 2 0 BOD
  • [3] Aniketos, 2011, DEL 6 1 IN AN IND CA
  • [4] [Anonymous], 1996, THESIS
  • [5] [Anonymous], 2011, NUMBER FORMAL 2011 0
  • [6] Backes M, 2003, LECT NOTES COMPUT SC, V2678, P168
  • [7] Tropos: An agent-oriented software development methodology
    Bresciani, P
    Perini, A
    Giorgini, P
    Giunchiglia, F
    Mylopoulos, J
    [J]. AUTONOMOUS AGENTS AND MULTI-AGENT SYSTEMS, 2004, 8 (03) : 203 - 236
  • [8] A Method for Eliciting Goals for Business Process Models Based on Non-Functional Requirements Catalogues
    Cardoso, Evellin
    Almeida, Joao Paulo A.
    Guizzardi, Renata S. S.
    Guizzardi, Giancarlo
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SYSTEM MODELING AND DESIGN, 2011, 2 (02) : 1 - 18
  • [9] Firesmith Donald., 2003, J OBJECT TECHNOL, V2, P53
  • [10] Designing and implementing cross-organizational business processes -: Description and application of a modelling framework
    Greiner, Ulrike
    Lippe, Sonia
    Kahl, Timo
    Ziemann, Joerg
    Jaekel, Frank-Walter
    [J]. ENTERPRISE INTEROPERABILITY: NEW CHALLENGES AND APPROACHES, 2007, : 137 - +