A formal top down model shall be presented to aid documentation and harmonization of information security requirements. The model formalizes layered development of information security, where top level abstract objectives, strategies and policies are step by step refined into concrete protection measure specifications. The model consists of static and dynamic parts, where static part refers to the organization, and dynamic part to the refinement of requirements. Major functions are horizontal and vertical harmonization functions used to transfer requirement into lower levels of abstraction, and to identify requirements of secure inter-operation of systems on each layer. Application of the model then consists of two parts: specification of the organization and specification of requirement harmonization functions.
CITATION STYLE
Leiwo, J., & Zheng, Y. (1997). A Formal model to aid documenting and harmonizing of information security requirements. In Information Security in Research and Business (pp. 25–38). Springer US. https://doi.org/10.1007/978-0-387-35259-6_3
Mendeley helps you to discover research relevant for your work.