DocumentCode
2131180
Title
Requirements Management in a Combined Process for Safety and Security Assessments
Author
Katta, Vikash ; Raspotnig, Christian ; Karpati, Peter ; Stalhane, Tor
Author_Institution
Dept. Software Eng., Inst. for Energy Technol., Halden, Norway
fYear
2013
fDate
2-6 Sept. 2013
Firstpage
780
Lastpage
786
Abstract
Combined Harm Assessment of Safety and Security for Information Systems (CHASSIS) method defines a unified process for safety and security assessments to address both the safety and security aspects during system development process. CHASSIS applies techniques from safety and security fields-e.g. misuse case and HAZOP-to identify and model hazards, threats and mitigations to a system. These mitigations, which are generally specified as safety and security requirements, are interrelated. Defining and maintaining the interdependencies between these requirements are vital to, among other things, estimate how a requirement impacts other requirements and artefacts. In this paper, we present our approach for providing trace ability to CHASSIS in order to capture the interdependencies between the safety and security requirements and to demonstrate the history and rational behind their elicitation. The approach, called Satrap, constitutes a process model defining what type of artefacts are generated during development and assessment activities, what type of relations between the artefacts should be captured, and how to extract traces. The trace ability approach together with its supporting prototype tool was applied on an Air Traffic Management remote tower example which was assessed for safety and security risks using CHASSIS.
Keywords
air traffic control; formal specification; risk management; security of data; traffic information systems; CHASSIS; SaTrAp; air traffic management remote tower; assessment activities; combined harm assessment of safety and security for information system method; development activities; process model; safety assessments; safety requirements management; safety risk; security assessments; security requirements management; security risk; traceability; traceability approach; Atmospheric modeling; Context; Hazards; Poles and towers; Security; Unified modeling language; ATM; UML; safety; security; traceability;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
Conference_Location
Regensburg
Type
conf
DOI
10.1109/ARES.2013.104
Filename
6657320
Link To Document