Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
Ergebnis 24 von 99

Details

Autor(en) / Beteiligte
Titel
A Customizable Framework for Prioritizing Systems Security Engineering Processes, Activities, and Tasks
Ist Teil von
  • IEEE access, 2017-01, Vol.5, p.12878-12894
Ort / Verlag
Piscataway: IEEE
Erscheinungsjahr
2017
Quelle
Elektronische Zeitschriftenbibliothek (Open access)
Beschreibungen/Notizen
  • As modern systems become increasingly complex, current security practices lack effective methodologies to adequately address the system security. This paper proposes a repeatable and tailorable framework to assist in the application of systems security engineering (SSE) processes, activities, and tasks as defined in the recently released National Institute of Standards and Technology (NIST) Special Publication 800-160. First, a brief survey of systems-oriented security methodologies is provided. Next, an examination of the relationships between the NIST-defined SSE processes is conducted to provide context for the engineering problem space. These findings inform a mapping of the NIST SSE processes to seven system-agnostic security domains which enable prioritization for three types of systems (conventional IT, cyber-physical, and defense). These concrete examples provide further understanding for applying and prioritizing the SSE effort. The goal of this paper is assist practitioners by informing the efficient application of the 30 processes, 111 activities, and 428 tasks defined in NIST SP 800-160. The customizable framework tool is available online for developers to employ, modify, and tailor to meet their needs.
Sprache
Englisch
Identifikatoren
ISSN: 2169-3536
eISSN: 2169-3536
DOI: 10.1109/ACCESS.2017.2714979
Titel-ID: cdi_ieee_primary_7979510

Weiterführende Literatur

Empfehlungen zum selben Thema automatisch vorgeschlagen von bX