Organisational security requirements : an agile approach to ubiquitous information security


Autoria(s): Ruighaver, A.B.
Contribuinte(s)

Valli, Craig

Woodward, Andre

Data(s)

01/01/2008

Resumo

This paper proposes to address the need for more innovation in organisational information security by adding a security requirement engineering focus. Based on the belief that any heavyweight security requirements process in organisational security will be doomed to fail, we developed a security requirement approach with three dimensions. The use of a simple security requirements process in the first dimension has been augmented by an agile security approach. However, introducing this second dimension of agile security does provide support for, but does not necessarily stimulate, innovation. A third dimension is, therefore, needed to ensure there is a proper focus in the organisation's efforts to identify potential new innovations in their security. To create this focus three common shortcomings in organisational information security have been identified. The resulting security approach that addresses these shortcomings is called Ubiquitous Information Security. This paper will demonstrate the potential of this new approach by briefly discussing its possible application in two areas: Ubiquitous Identity Management and Ubiquitous Wireless Security.<br />

Identificador

http://hdl.handle.net/10536/DRO/DU:30018301

Idioma(s)

eng

Publicador

Edith Cowan University

Relação

http://dro.deakin.edu.au/eserv/DU:30018301/ruighaver-organisationalsecurity-2008.pdf

http://igneous.scis.ecu.edu.au/proceedings/2008/aism/Ruighaver%20Organisational%20Security%20Requirements.pdf

Direitos

2008, Edith Cowan University

Palavras-Chave #security requirement engineering #agile security #ubiquitous security #ubiquitous identity management #wireless intrusion detection
Tipo

Conference Paper