Abstract
Security involves technical as well as social challenges. In the development of security-critical applications, system developers must consider both the technical and the social parts. To achieve this, security issues must be considered during the whole development life-cycle of an information system. This paper presents an approach that allows developers to consider both the social and the technical dimensions of security through a structured and well defined process. In particular, the proposed approach takes the high-level concepts and modelling activities of the secure Tropos methodology and enriches them with a low level security-engineering ontology and models derived from the UMLsec approach. A real case study from the e-commerce sector is employed to demonstrate the applicability of the approach. © Springer-Verlag Berlin Heidelberg 2006.
Cite
CITATION STYLE
Mouratidis, H., Jürjens, J., & Fox, J. (2006). Towards a comprehensive framework for secure systems development. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 4001 LNCS, pp. 48–62). Springer Verlag. https://doi.org/10.1007/11767138_5
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.