Title of article
Requirements-based Access Control Analysis and Policy Specification (ReCAPS)
Author/Authors
He، نويسنده , , Qingfeng and Antَn، نويسنده , , Annie I.، نويسنده ,
Issue Information
ماهنامه با شماره پیاپی سال 2009
Pages
17
From page
993
To page
1009
Abstract
Access control (AC) is a mechanism for achieving confidentiality and integrity in software systems. Access control policies (ACPs) express rules concerning who can access what information, and under what conditions. ACP specification is not an explicit part of the software development process and is often isolated from requirements analysis activities, leaving systems vulnerable to security breaches because policies are specified without ensuring compliance with system requirements. In this paper, we present the Requirements-based Access Control Analysis and Policy Specification (ReCAPS) method for deriving and specifying ACPs, and discuss three validation efforts. The method integrates policy specification into the software development process, ensures consistency across software artifacts, and provides prescriptive guidance for how to specify ACPs. It also improves the quality of requirements specifications and system designs by clarifying ambiguities and resolving conflicts across these artifacts during the analysis, making a significant step towards ensuring that policies are enforced in a manner consistent with a system’s requirements specifications. To date, the method has been applied within the context of four operational systems. Additionally, we have conducted an empirical study to evaluate its usefulness and effectiveness. A software tool, the Security and Privacy Requirements Analysis Tool (SPRAT), was developed to support ReCAPS analysis activities.
Keywords
Requirements Analysis , SECURITY , Access control
Journal title
Information and Software Technology
Serial Year
2009
Journal title
Information and Software Technology
Record number
2374498
Link To Document