• DocumentCode
    2131180
  • Title

    Requirements Management in a Combined Process for Safety and Security Assessments

  • Author

    Katta, Vikash ; Raspotnig, Christian ; Karpati, Peter ; Stalhane, Tor

  • Author_Institution
    Dept. Software Eng., Inst. for Energy Technol., Halden, Norway
  • fYear
    2013
  • fDate
    2-6 Sept. 2013
  • Firstpage
    780
  • Lastpage
    786
  • Abstract
    Combined Harm Assessment of Safety and Security for Information Systems (CHASSIS) method defines a unified process for safety and security assessments to address both the safety and security aspects during system development process. CHASSIS applies techniques from safety and security fields-e.g. misuse case and HAZOP-to identify and model hazards, threats and mitigations to a system. These mitigations, which are generally specified as safety and security requirements, are interrelated. Defining and maintaining the interdependencies between these requirements are vital to, among other things, estimate how a requirement impacts other requirements and artefacts. In this paper, we present our approach for providing trace ability to CHASSIS in order to capture the interdependencies between the safety and security requirements and to demonstrate the history and rational behind their elicitation. The approach, called Satrap, constitutes a process model defining what type of artefacts are generated during development and assessment activities, what type of relations between the artefacts should be captured, and how to extract traces. The trace ability approach together with its supporting prototype tool was applied on an Air Traffic Management remote tower example which was assessed for safety and security risks using CHASSIS.
  • Keywords
    air traffic control; formal specification; risk management; security of data; traffic information systems; CHASSIS; SaTrAp; air traffic management remote tower; assessment activities; combined harm assessment of safety and security for information system method; development activities; process model; safety assessments; safety requirements management; safety risk; security assessments; security requirements management; security risk; traceability; traceability approach; Atmospheric modeling; Context; Hazards; Poles and towers; Security; Unified modeling language; ATM; UML; safety; security; traceability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
  • Conference_Location
    Regensburg
  • Type

    conf

  • DOI
    10.1109/ARES.2013.104
  • Filename
    6657320