DocumentCode
2128693
Title
Discovering and Understanding Multi-dimensional Correlations among Certification Requirements with application to Risk Assessment
Author
Gandhi, Robin A. ; Lee, Seok-Won
fYear
2007
fDate
15-19 Oct. 2007
Firstpage
231
Lastpage
240
Abstract
In this paper we outline our approach to discover and understand multi-dimensional correlations among regulatory security certification requirements in the context of a complex software system. A thorough understanding of these correlations is necessary to assure that diverse constraints imposed by numerous certification requirements are adequate for collectively contributing to emergent security properties in a highly interconnected socio-technical environment. We elaborate on methodological support to discover an exhaustive set of applicable certification requirements in a given operational scenario of the target software system. We then describe techniques to systematically understand the multi-dimensional correlations among these requirements with application to security risk assessment. The case study of applying our approach to a regulatory certification process of The United States Department of Defense (DoD) is presented.
Keywords
Accreditation; Application software; Certification; Government; Information security; Information systems; Natural languages; Risk management; Software systems; USA Councils;
fLanguage
English
Publisher
ieee
Conference_Titel
Requirements Engineering Conference, 2007. RE '07. 15th IEEE International
Conference_Location
Delhi
ISSN
1090-705X
Print_ISBN
978-0-7695-2935-6
Type
conf
DOI
10.1109/RE.2007.46
Filename
4384186
Link To Document