Towards a comprehensive framework for secure systems development

  • Authors:
  • Haralambos Mouratidis;Jan Jürjens;Jorge Fox

  • Affiliations:
  • Innovative Informatics, School of Computing and Technology, University of East London, UK;Software and Systems Engineering, TU Munich, Germany;Software and Systems Engineering, TU Munich, Germany

  • Venue:
  • CAiSE'06 Proceedings of the 18th international conference on Advanced Information Systems Engineering
  • Year:
  • 2006

Quantified Score

Hi-index 0.01

Visualization

Abstract

Security involves technical as well as social challenges. In the development of security-critical applications, system developers must consider both the technical and the social parts. To achieve this, security issues must be considered during the whole development life-cycle of an information system. This paper presents an approach that allows developers to consider both the social and the technical dimensions of security through a structured and well defined process. In particular, the proposed approach takes the high-level concepts and modelling activities of the secure Tropos methodology and enriches them with a low level security-engineering ontology and models derived from the UMLsec approach. A real case study from the e-commerce sector is employed to demonstrate the applicability of the approach.