• DocumentCode
    2131313
  • Title

    Beyond Traceability: Compared Approaches to Consistent Security Risk Assessments

  • Author

    Bergomi, Franco ; Paul, Sudipta ; Solhaug, Bjornar ; Vignon-Davillier, Raphael

  • Author_Institution
    Thales Global Services, Eng. Shared Services, Meudon-La-Foret, France
  • fYear
    2013
  • fDate
    2-6 Sept. 2013
  • Firstpage
    814
  • Lastpage
    820
  • Abstract
    As military and civil software-intensive information systems grow and become more and more complex, structured approaches, called architecture frameworks (AF), were developed to support their engineering. The concepts of these approaches were standardised under ISO/IEC 42010 - Systems and Software Engineering - Architecture Description. An Architecture Description is composed of Views, where each View addresses one or more engineering concerns. As mentioned in the standard, a multi-viewpoint approach requires the capacity to capture the different views, and maintain their mutual consistency. This paper addresses primarily the problem of integrating a model-based security risk assessment view to the mainstream system engineering view(s) and, to a lesser extent, the problem of maintaining the overall consistency of the views. Both business stakes and technical means are studied. We present two specific approaches, namely CORAS and Rinforzando. Both come with techniques and tool support to facilitate security risk assessment of complex and evolving critical infrastructures, such as ATM systems. The former approach offers static import/export relationships between artefacts, whereas the latter offers dynamic relationships. The pros and cons of each technical approach are discussed.
  • Keywords
    IEC standards; ISO standards; risk management; security of data; software architecture; systems engineering; AF; ATM systems; CORAS; ISO/IEC 42010; Rinforzando; architecture description; architecture frameworks; civil software-intensive information system; dynamic relationships; mainstream system engineering view; military software-intensive information system; model-based security risk assessment view; multiviewpoint approach; mutual consistency; security risk assessments; software engineering; static export relationships; static import relationships; systems engineering; Analytical models; Computer architecture; Documentation; Risk management; Runtime; Security; ATM; Model-driven security; critical infrastructures; risk assessment; risk modelling; security management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
  • Conference_Location
    Regensburg
  • Type

    conf

  • DOI
    10.1109/ARES.2013.109
  • Filename
    6657325