Security Requirements Elicitation from Airline Turnaround Processes

被引:4
|
作者
Matulevicius, Raimundas [1 ]
Norta, Alex [2 ]
Samarutel, Silver [1 ]
机构
[1] Univ Tartu, Tartu, Estonia
[2] Tallinn Univ Technol, Tallinn, Estonia
来源
BUSINESS & INFORMATION SYSTEMS ENGINEERING | 2018年 / 60卷 / 01期
关键词
Security risk management; Security patterns; Security requirements engineering; Airline turnaround process; BUSINESS PROCESSES; ENGINEERING PROCESS; MANAGEMENT; EXTENSION; SYSTEMS; DOMAIN;
D O I
10.1007/s12599-018-0518-4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security risk management is an important part of system development. Given that a majority of modern organizations rely heavily on information systems, security plays a big part in ensuring smooth operations of business processes. For example, many people rely on e-services offered by banks and medical establishments. Inadequate security measures in information systems have unwanted effects on an organization's reputation and on people's lives. This case study paper targets the secure system development problem by suggesting the application of security requirements elicitation from business processes (SREBP). This approach provides business analysts with means to elicit and introduce security requirements to business processes through the application of the security risk-oriented patterns (SRPs). These patterns help find security risk occurrences in business processes and present mitigations for these risks. At the same time, they reduce the efforts needed for risk analysis. In this paper, the authors report their experience to derive security requirements for mitigating security risks in the distributed airline turnaround systems.
引用
收藏
页码:3 / 20
页数:18
相关论文
共 50 条
  • [1] Security Requirements Elicitation from Airline Turnaround Processes
    Raimundas Matulevičius
    Alex Norta
    Silver Samarütel
    Business & Information Systems Engineering, 2018, 60 : 3 - 20
  • [2] Security Requirements Elicitation from Business Processes
    Matulevicius, Raimundas
    BUSINESS PROCESS MANAGEMENT WORKSHOPS( BPM 2014), 2015, 202
  • [3] Assessment of Aviation Security Risk Management for Airline Turnaround Processes
    Matulevicius, Raimundas
    Norta, Alex
    Udokwu, Chibuzor
    Noukas, Rein
    TRANSACTIONS ON LARGE-SCALE DATA- AND KNOWLEDGECENTERED SYSTEMS XXXVI: SPECIAL ISSUE ON DATA AND SECURITY ENGINEERING, 2018, 10720 : 109 - 141
  • [4] Presentation and Validation of Method for Security Requirements Elicitation from Business Processes
    Ahmed, Naved
    Matulevicius, Raimundas
    INFORMATION SYSTEMS ENGINEERING IN COMPLEX ENVIRONMENTS, 2015, 204 : 20 - 35
  • [5] Securing Airline-Turnaround Processes Using Security Risk-Oriented Patterns
    Samarutel, Silver
    Matulevicius, Raimundas
    Norta, Alex
    Noukas, Rein
    PRACTICE OF ENTERPRISE MODELING, POEM 2016, 2016, 267 : 209 - 224
  • [6] A Security Ontology for Security Requirements Elicitation
    Souag, Amina
    Salinesi, Camille
    Mazo, Raul
    Comyn-Wattiau, Isabelle
    ENGINEERING SECURE SOFTWARE AND SYSTEMS (ESSOS 2015), 2015, 8978 : 157 - 175
  • [7] Security Requirements Elicitation and Modeling Authorizations
    Goel, Rajat
    Govil, Mahesh Chandra
    Singh, Girdhari
    SECURITY IN COMPUTING AND COMMUNICATIONS, SSCC 2016, 2016, 625 : 239 - 250
  • [8] Automatic requirements elicitation in agile processes
    Ankori, R
    IEEE INTERNATIONAL CONFERENCE ON SOFTWARE - SCIENCE, TECHNOLOGY AND ENGINEERING, PROCEEDINGS, 2005, : 101 - 109
  • [9] Integrating business processes with requirements elicitation
    Fiorini, ST
    Leite, JCSD
    deMacedoSoares, TDL
    PROCEEDINGS OF THE 5TH WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES (WET ICE '96), 1996, : 226 - 231
  • [10] Security Requirements Elicitation from Engineering Governance, Risk Management and Compliance
    Ghiran, Ana-Maria
    Buchmann, Robert Andrei
    Osman, Cristina-Claudia
    REQUIREMENTS ENGINEERING: FOUNDATION FOR SOFTWARE QUALITY (REFSQ 2018), 2018, 10753 : 283 - 289