A Comparison of the Common Criteria with Proposals of Information Systems Security Requirements

  • Authors:
  • Daniel Mellado;Eduardo Fernandez-Medina;Mario Piattini

  • Affiliations:
  • Quality, Auditing and Security Institute, Madrid, Spain;UCLM-Soluziona Research and Development Institute, Spain;UCLM-Soluziona Research and Development Institute, Spain

  • Venue:
  • ARES '06 Proceedings of the First International Conference on Availability, Reliability and Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.04

Visualization

Abstract

Nowadays, security solutions are focused mainly on providing security defences, instead of solving one of the main reasons for security problems that refers to an appropriate Information Systems (IS) design. Fortunately there are several standards, like the Common Criteria, which help to deal with the security requirements along all the IS development cycle. In this paper a comparative analysis of eight different relevant technical proposals, which place great importance on the establishing of security requirements in the development of IS, is carried out. And they provide some significant contributions in aspects related to security. Nevertheless, they only satisfy partly the necessary criteria for the establishment of security requirements, with guarantees and integration in the development of IS. Thus we conclude that they are not specific enough for dealing with security requirements in the first stages of IS development in a systematic and intuitive way.