Towards a formal specification method for enterprise information system security

  • Authors:
  • Anirban Sengupta;Mridul Sankar Barik

  • Affiliations:
  • Centre for Distributed Computing, Jadavpur University, Kolkata, India;Dept. of Comp. Sc. & Engg., Jadavpur University, Kolkata, India

  • Venue:
  • ICISS'06 Proceedings of the Second international conference on Information Systems Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

As information infrastructure is becoming more and more complex, and connected, the security properties like confidentiality, integrity and availability are becoming more and more difficult to protect. The international community is adopting security standards such as ISO 17799 for best practices in security management and Common Criteria for security certification of IT products. It has been recognized that the security of enterprises has to be tackled from the point of view of a management structure than from a purely technological angle, and to achieve this, the primary need is to have a comprehensive security policy. A security model is a formal way of capturing such security policies. Most existing security models cannot support a wide range of security policies. The need is to develop a formal security model that combines the intricacies of the entire gamut of existing security models and supports security policies for a wide range of enterprises.