Report: modular safeguards to create holistic security requirement specifications for system of systems

  • Authors:
  • Albin Zuccato;Nils Daniels;Cheevarat Jampathom;Mikael Nilson

  • Affiliations:
  • TeliaSonera, Common Development, Product Security, Sweden;TeliaSonera, Common Development, Product Security, Sweden;TeliaSonera, Common Development, Product Security, Sweden;TeliaSonera, Common Development, Product Security, Sweden

  • Venue:
  • ESSoS'10 Proceedings of the Second international conference on Engineering Secure Software and Systems
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

The specification of security requirements for systems of systems is often an activity that is forced upon non-security experts and performed under time pressure. This paper describes how we have addressed this problem by using a collection of modular safeguards, which are tailored to the application domain. These safeguards, which are specific but still fairly atomic, are combined into requirement profiles that seamlessly integrate into the overall development approach. These safeguards are grouped into 15 classes which subsume requirements that aim for low, medium and high security capabilities. Each requirement is further specified with a technical description defining actual values. To achieve a holistic coverage, we have created requirement profiles that define combinations of modular safeguards and have added complementary organizational safeguards. We will show how we have developed this approach over the years and present our practical experiences of the seamless integration into the development life cycle.