|
|
Aligning Security and Privacy to Support the Development of Secure Information Systems
|
|
|
|
|
نویسنده
|
Mouratidis Haralambos ,Kalloniatis Christos ,Islam Shareeful ,Huget Marc-Philippe ,Gritzalis Stefanos
|
منبع
|
journal of universal computer science - 2012 - دوره : 18 - شماره : 12 - صفحه:1608 -1627
|
چکیده
|
The increasing dependency on information systems to process and manage sensitive information requires the usage of development methods that support the development of secure and private information systems. the literature provides examples of methods that focus on security and privacy individually but fail to provide evidence of information systems development methods that consider security and privacy in a unified framework. security and privacy are very much related, in particular certain security properties and mechanisms support the achievement of privacy goals. without a development framework to support developers to explicitly model that relationship, conflicts and vulnerabilities can be introduced to a system design that might endanger its security. in this paper, we present our work in developing a framework that supports the unified analysis of privacy and security. in particular, we present a meta-model that combines concepts from security and privacy requirements methods, such as security and privacy goals, properties, constraints, and actor and process patterns within a social context. a real case study is employed to demonstrate the applicability of our work.
|
کلیدواژه
|
Security ,privacy ,constraints ,goal modelling ,meta-model
|
آدرس
|
University of East London, School of Architecture, Computing and Engineering, UK, University of the Aegean, Cultural Informatics Laboratory, Dept of Cultural Technology and Communication, Greece, University of East London, School of Architecture, Computing, and Engineering, UK, University of Savoie, LISTIC/ Polytech Annecy-Chambéry, France, University of the Aegean, Laboratory of Information and Communication Systems Security, Dept of Information and Communications Systems Engineering, Greece
|
پست الکترونیکی
|
sgritz@aegean.gr
|
|
|
|
|
|
|
|
|
|
|
|
Authors
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|