DocumentCode
2416895
Title
An Enterprise Level Security Requirements Specification Model
Author
Anderson, Evan ; Choobineh, Joobin ; Grimaila, Michael R.
Author_Institution
Texas A&M University; College Station, TX
fYear
2005
fDate
03-06 Jan. 2005
Abstract
A formal model of security requirements for enterprise information technology protection is developed. The model is based on set theory and represented using an Entity-Relationship diagram. Components of the model include high level business objectives and their criticality, business requirements and their utilization, resources and their characterization as protector or protected resources, controls and their effectiveness, threats, vulnerabilities, potential exploits, and the resulting impact. An example representation of a formal relationship is provided. The model provides a canonical representation of enterprise security, enables automation and hence rigorous analysis of the security cost and effectiveness, provides for completeness and consistency checking, and offers a means for what-if as well as comparative analysis of security readiness.
Keywords
Automatic control; Automation; Costs; Data security; Electronic mail; Information security; Information technology; Protection; Resource management; Set theory;
fLanguage
English
Publisher
ieee
Conference_Titel
System Sciences, 2005. HICSS '05. Proceedings of the 38th Annual Hawaii International Conference on
ISSN
1530-1605
Print_ISBN
0-7695-2268-8
Type
conf
DOI
10.1109/HICSS.2005.88
Filename
1385614
Link To Document