Cristin-resultat-ID: 1088721
Sist endret: 15. januar 2014, 08:08
NVI-rapporteringsår: 2013
Resultat
Vitenskapelig Kapittel/Artikkel/Konferanseartikkel
2013

Beyond Traceability: Compared Approaches to Consistent Security Risk Assessments

Bidragsytere:
  • Franco Bergomi
  • Stéphane Paul
  • Bjørnar Solhaug og
  • Raphael Vignon-Davillier

Bok

2013 Eighth International Conference on Availability, Reliability and Security (ARES), Regensburg, 2-6 September 2013
ISBN:
  • 978-0-7695-5008-4

Utgiver

IEEE (Institute of Electrical and Electronics Engineers)
NVI-nivå 1

Om resultatet

Vitenskapelig Kapittel/Artikkel/Konferanseartikkel
Publiseringsår: 2013
Sider: 814 - 820
ISBN:
  • 978-0-7695-5008-4

Klassifisering

Fagfelt (NPI)

Fagfelt: IKT
- Fagområde: Realfag og teknologi

Beskrivelse Beskrivelse

Tittel

Beyond Traceability: Compared Approaches to Consistent Security Risk Assessments

Sammendrag

As military and civil software-intensive infor- mation systems grow and become more and more complex, structured approaches, called architecture frameworks (AF), were developed to support their engineering. The concepts of these approaches were standardised under ISO/IEC 42010 – Systems and Software Engineering – Architecture Description. An Architecture Description is composed of Views, where each View addresses one or more engineering concerns. As mentioned in the standard, a multi-viewpoint approach requires the capacity to capture the different views, and maintain their mutual consistency. This paper addresses primarily the problem of integrating a model-based security risk assessment view to the mainstream system engineering view(s) and, to a lesser extent, the problem of maintaining the overall consistency of the views. Both business stakes and technical means are studied. We present two specific approaches, namely CORAS and Rinforzando. Both come with techniques and tool support to facilitate security risk assessment of complex and evolving critical infrastructures, such as ATM systems. The former approach offers static import/export relationships between artefacts, whereas the latter offers dynamic relationships. The pros and cons of each technical approach are discussed.

Bidragsytere

Franco Bergomi

  • Tilknyttet:
    Forfatter
    ved Thales

Stéphane Paul

  • Tilknyttet:
    Forfatter
    ved Thales

Bjørnar Solhaug

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS

Raphael Vignon-Davillier

  • Tilknyttet:
    Forfatter
    ved Thales
1 - 4 av 4

Resultatet er en del av Resultatet er en del av

2013 Eighth International Conference on Availability, Reliability and Security (ARES), Regensburg, 2-6 September 2013.

Guerrero, Juan E.. 2013, IEEE (Institute of Electrical and Electronics Engineers). Vitenskapelig antologi/Konferanseserie
1 - 1 av 1