• DocumentCode
    2128693
  • Title

    Discovering and Understanding Multi-dimensional Correlations among Certification Requirements with application to Risk Assessment

  • Author

    Gandhi, Robin A. ; Lee, Seok-Won

  • fYear
    2007
  • fDate
    15-19 Oct. 2007
  • Firstpage
    231
  • Lastpage
    240
  • Abstract
    In this paper we outline our approach to discover and understand multi-dimensional correlations among regulatory security certification requirements in the context of a complex software system. A thorough understanding of these correlations is necessary to assure that diverse constraints imposed by numerous certification requirements are adequate for collectively contributing to emergent security properties in a highly interconnected socio-technical environment. We elaborate on methodological support to discover an exhaustive set of applicable certification requirements in a given operational scenario of the target software system. We then describe techniques to systematically understand the multi-dimensional correlations among these requirements with application to security risk assessment. The case study of applying our approach to a regulatory certification process of The United States Department of Defense (DoD) is presented.
  • Keywords
    Accreditation; Application software; Certification; Government; Information security; Information systems; Natural languages; Risk management; Software systems; USA Councils;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Requirements Engineering Conference, 2007. RE '07. 15th IEEE International
  • Conference_Location
    Delhi
  • ISSN
    1090-705X
  • Print_ISBN
    978-0-7695-2935-6
  • Type

    conf

  • DOI
    10.1109/RE.2007.46
  • Filename
    4384186