Integrating information security engineering with system engineering with system engineering tools

被引:2
作者
Higginbotham, MD [1 ]
Maley, JG [1 ]
Milheizler, AJ [1 ]
Suskie, BJ [1 ]
机构
[1] Booz Allen & Hamilton Inc, Mclean, VA 22102 USA
来源
SEVENTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES (WET ICE '98) | 1998年
关键词
D O I
10.1109/ENABL.1998.725712
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Users of Automated Information Systems (AISs) ave becoming increasingly aware of the inherent risk associated with placing sensitive information on a system. Users are beginning to demand an assessment of the quality of security services offered because they need to make informed decisions on accepting certain levels of risk associated with protecting information they place on a system. By integrating an Information System Security Engineering (ISSE) process' into system development or system enhancement activities, system developers can satisfy user concerns. An ISSE process will identify the quality of security services needed by users, help identify security mechanisms to satisfy user needs; lead to an effective security design; identify the quality of security services offered by the actual system, and develop the documentation necessary to effectively market the security services offered by a system. An effective and cast efficient method for managing and providing discipline for the ISSE process is for system developers to use an automated system engineering tool. Such a tool significantly enhances the system security engineering team's ability to satisfy user security needs throughout the system design process.
引用
收藏
页码:320 / 326
页数:7
相关论文
empty
未找到相关数据