Eliciting Policy Requirements for Critical National Infrastructure Using the IRIS Framework

Shamal Faily, I. Flechais
{"title":"Eliciting Policy Requirements for Critical National Infrastructure Using the IRIS Framework","authors":"Shamal Faily, I. Flechais","doi":"10.4018/JSSE.2011100101","DOIUrl":null,"url":null,"abstract":"Despite existing work on dealing with security and usability concerns during the early stages of design, there has been little work on synthesising the contributions of these fields into processes for specifying and designing systems. Without a better understanding of how to deal with both concerns at an early stage, the design process risks disenfranchising stakeholders, and resulting systems may not be situated in their contexts of use. This paper presents the IRIS process framework, which guides technique selection when specifying usable and secure systems. The authors illustrate the framework by describing a case study where the process framework was used to derive missing requirements for an information security policy for a UK water company following reports of the Stuxnet worm. The authors conclude with three lessons informing future efforts to integrate Security, Usability, and Requirements Engineering techniques for secure system design.","PeriodicalId":89158,"journal":{"name":"International journal of secure software engineering","volume":"157 1","pages":"1-18"},"PeriodicalIF":0.0000,"publicationDate":"2011-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal of secure software engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/JSSE.2011100101","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

Despite existing work on dealing with security and usability concerns during the early stages of design, there has been little work on synthesising the contributions of these fields into processes for specifying and designing systems. Without a better understanding of how to deal with both concerns at an early stage, the design process risks disenfranchising stakeholders, and resulting systems may not be situated in their contexts of use. This paper presents the IRIS process framework, which guides technique selection when specifying usable and secure systems. The authors illustrate the framework by describing a case study where the process framework was used to derive missing requirements for an information security policy for a UK water company following reports of the Stuxnet worm. The authors conclude with three lessons informing future efforts to integrate Security, Usability, and Requirements Engineering techniques for secure system design.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
利用IRIS框架引出关键国家基础设施的政策要求
尽管现有的工作是在设计的早期阶段处理安全性和可用性问题,但很少有工作是将这些领域的贡献综合到指定和设计系统的过程中。如果没有在早期阶段更好地理解如何处理这两个问题,设计过程就有可能剥夺涉众的权利,并且最终的系统可能不适合它们的使用环境。本文介绍了IRIS过程框架,它在指定可用和安全的系统时指导技术选择。作者通过描述一个案例研究来说明这个框架,在这个案例研究中,过程框架被用来推导出在Stuxnet蠕虫报告之后,英国一家水务公司的信息安全策略的缺失需求。作者总结了三个经验教训,告知未来为安全系统设计集成安全性、可用性和需求工程技术的努力。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Analysis of Existing Software Cognitive Complexity Measures Risk Centric Activities in Secure Software Development in Public Organisations LDAP Vulnerability Detection in Web Applications A Database of Existing Vulnerabilities to Enable Controlled Testing Studies Goal Modelling for Security Problem Matching and Pattern Enforcement
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1