A business process-driven approach to security engineering

  • Authors:
  • Antonio Maña;José A. Montenegro;Carsten Rudolph;José Luis Vivas

  • Affiliations:
  • -;-;-;-

  • Venue:
  • DEXA '03 Proceedings of the 14th International Workshop on Database and Expert Systems Applications
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

A challenging task in security engineering concerns thespecification and integration of security with other requirementsat the top level of requirements engineering. Empiricalstudies show that it is common that end users areable to express their security needs at the business processlevel. Since many security requirements originate at thislevel, it is natural to try to capture and express them withinthe context of business models where end users feel mostcomfortable and where they conceptually belong. In thispaper we develop these views, present an ongoing work intendedto create a UML-based and business process-drivenframework for the development of security-critical systemsand propose an approach to a rigorous treatment of securityrequirements supported by formal methods.