【24h】

Extracting Security Control Requirements

机译:提取安全控制要求

获取原文

摘要

Expressing security controls as functional requirements aids in the verification step of security certification and accreditation. Distributed, multi-component systems or systems of systems (SoSs) are difficult to verify because the security controls must be understood in functional terms with respect to their local effects on components, their global effects on the SoS, and their effect on component information exchange. In this paper, we define a process to formulate functional requirements from security controls with SoSs as the target. The process starts by extracting model elements associated with assets, functions, organization variables, and external influences. These models are composed across a set of security controls and normalized to maintain consistency and remove redundancies. We apply the models to SoSs to provide essential details to their specification in functional requirements. The objective is to reduce ambiguity when verifying SoSs as well as minimize recertification efforts when the system or security expectations changes.
机译:表达安全控件功能要求有助于安全认证和认可的验证步骤。分布式,多组分系统或系统的系统(索斯)难以验证,因为安全控制必须在功能方面相对于被理解为对部件的局部效应,它们对的SoS全局效果,以及它们对部件信息交换作用。在本文中,我们定义了一个过程与索斯制定的安全控制功能要求为目标。该过程通过提取与资产,职能,组织变量和外部影响有关的模型元素开始。这些模型在一组安全控制的组成和标准化,以保持一致性,并消除冗余。我们应用模型索斯提供的功能要求他们规范重要细节。其目的是验证索斯时减少模糊性以及减少换证工作,当系统或安全预期的变化。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号