TY - GEN
T1 - Security engineering methodology for developing secure enterprise information systems
T2 - 7th International Conference on Embedded and Multimedia Computing, EMC 2012
AU - Kim, Young Gab
AU - Cha, Sungdeok
PY - 2012
Y1 - 2012
N2 - The software engineering discipline has provided principles, methodologies, and tools for the development of information systems. Software engineering have also become a fundamental component to produce information systems and related software components which are cheaper, better and faster. Recently, many forms of security attacks against information systems have emerged that attempt to compromise the security of information systems and organizations. However, traditional software engineering is not adequate and effective for developing secure information systems. In this paper, we propose holistic, consistent, and integrated security engineering procedures for analyzing, designing, developing, testing, and maintaining secure enterprise information systems. The proposed security engineering methodology combines security risk control, enterprise security architecture, and security management as an integrated framework.
AB - The software engineering discipline has provided principles, methodologies, and tools for the development of information systems. Software engineering have also become a fundamental component to produce information systems and related software components which are cheaper, better and faster. Recently, many forms of security attacks against information systems have emerged that attempt to compromise the security of information systems and organizations. However, traditional software engineering is not adequate and effective for developing secure information systems. In this paper, we propose holistic, consistent, and integrated security engineering procedures for analyzing, designing, developing, testing, and maintaining secure enterprise information systems. The proposed security engineering methodology combines security risk control, enterprise security architecture, and security management as an integrated framework.
KW - enterprise security architecture
KW - secure information system
KW - security engineering
KW - security management
KW - security risk analysis
UR - http://www.scopus.com/inward/record.url?scp=84867476521&partnerID=8YFLogxK
U2 - 10.1007/978-94-007-5076-0_47
DO - 10.1007/978-94-007-5076-0_47
M3 - Conference contribution
AN - SCOPUS:84867476521
SN - 9789400750753
T3 - Lecture Notes in Electrical Engineering
SP - 393
EP - 400
BT - Embedded and Multimedia Computing Technology and Service, EMC 2012
Y2 - 6 September 2012 through 8 September 2012
ER -