| Establishing trustworthiness in services of the critical infrastructure through certification and accreditation |
| Full text |
Pdf
(398 KB)
|
| Source
|
ACM SIGSOFT Software Engineering Notes
archive
Volume 30 , Issue 4 (July 2005)
table of contents
SESSION: Software Engineering for Secure Systems (SESS) --- Building Trustworthy Applications
table of contents
Pages: 1 - 7
Year of Publication: 2005
ISSN:0163-5948
Also published in ...
|
|
Authors
|
|
Seok Won Lee
|
The University of North Carolina at Charlotte, Charlotte, NC
|
|
Robin A. Gandhi
|
The University of North Carolina at Charlotte, Charlotte, NC
|
|
Gail-Joon Ahn
|
The University of North Carolina at Charlotte, Charlotte, NC
|
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 15, Downloads (12 Months): 100, Citation Count: 1
|
|
|
ABSTRACT
Trustworthiness in services provided by the Critical Infrastructure (CI) is essentially dependent on the quality of underlying software, systems, practice and environment, as which the software information infrastructures are becoming increasingly a major component of business, industry, government and defense. The level of trustworthiness required from services that are operational in such critical software information infrastructures is often established based on standardized infrastructure-wide evaluation criteria - Certification and Accreditation (C&A) - through the identification of operational risks and the determination of conformance with established security standards and best practices. In order to effectively establish such levels of trustworthiness for services in the CI, we identify the need for a structured and comprehensive C&A framework with appropriate tool support that combines its theoretical and practical aspects. In this paper, we present our efforts in developing such a framework that leverages novel techniques from software requirements engineering and knowledge engineering to support the automation of the Department of Defense Information Technology Security Certification and Accreditation Process (DITSCAP), which is a standard for certifying and accrediting the information networks that support the Defense Information Infrastructure (DII). Through the examples derived from our case study, we further motivate the applicability and appropriateness of our framework.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
CNSS 4009. National Information Assurance Glossary. NSA, 2003.
|
| |
2
|
DoD 8510. I-M. DITSCAP Application Manual. July 2000.
|
| |
3
|
DoD 8500. 1. Information Assurance. Oct. 2002.
|
| |
4
|
DoD 5200.40. DITSCAP. December 1997.
|
| |
5
|
DoD 8500.2. Information Assurance Implementation. Feb. 2003.
|
| |
6
|
Kimbell, J. and Walrath, M. Life Cycle Security and DITSCAP. IANewsletter, Vol. 4(2), Spring 2001.
|
| |
7
|
Kotonya, G. and Sommerville, I. Requirements Engineering with Viewpoints. BCS/IEE Software Engineering Journal, pp. 5--18, Vol. Il, Issue: 1, Jan. 1996.
|
| |
8
|
Lee, S. W., Ahn, G. and Gandhi, R. A. Engineering Information Assurance for Critical Infrastructures: The DITSCAP Automation Study. In Proceedings of the Fifteenth Annual International Symposium of the International Council on Systems Engineering (INCOSE '05), Rochester, NY, July 10--15. 2005.
|
| |
9
|
Lee, S. W. and Rine, D. C. Missing Requirements and Relationship Discovery through Proxy Viewpoints Model. Studia Informatica Universalis: Int'l. Journal on Informatics, Spring 2005.
|
| |
10
|
Lee, S. W. and Yavagal, D. GenOM User's Guide. Technical Report TR-SIS-NISE-04-01, Dept. of Software and Information Systems, UNC Charlotte, Spring 2004.
|
| |
11
|
Office of Management and Budget (OMB) Circular No. A-130. Management of Federal Information Resources, 1996.
|
| |
12
|
|
| |
13
|
Swanson, M. Guide for Developing Security Plans for Information Technology Systems. NIST Special Publication 800--18, 1998.
|
CITED BY
|
|
Seok-Won Lee , Robin Gandhi , Divya Muthurajan , Deepak Yavagal , Gail-Joon Ahn, Building problem domain ontology from security requirements in regulatory documents, Proceedings of the 2006 international workshop on Software engineering for secure systems, May 20-21, 2006, Shanghai, China
|
|