ACM Home Page
Please provide us with feedback. Feedback
Common criteria requirements modeling and its uses for quality of information assurance (QoIA)
Full text PdfPdf (563 KB)
Source ACM Southeast Regional Conference archive
Proceedings of the 43rd annual Southeast regional conference - Volume 2 table of contents
Kennesaw, Georgia
SESSION: Security table of contents
Pages: 130 - 135  
Year of Publication: 2005
ISBN:1-59593-059-0
Authors
Deepak S. Yavagal  The University of North Carolina at Charlotte, Charlotte, NC
Seok Won Lee  The University of North Carolina at Charlotte, Charlotte, NC
Gail-Joon Ahn  The University of North Carolina at Charlotte, Charlotte, NC
Robin A. Gandhi  The University of North Carolina at Charlotte, Charlotte, NC
Sponsor
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 25,   Downloads (12 Months): 125,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1167253.1167287
What is a DOI?

ABSTRACT

The Common Criteria for Information Technology Security Evaluation (CCITSE), usually referred to as the Common Criteria (CC), establishes a level of trustworthiness and confidence that should be placed in the security functions of products or systems and the assurance measures applied to them. CC achieves this by evaluating the product or system conformance with a common set of requirements set forth by it. To engineer a product that meets the information assurance goals of CC, a structured and comprehensive methodology is required to drive the activities undertaken in all the stages of the software requirements engineering (RE) process. Such a methodology is inevitable to understand and attain the Quality of Information Assurance (QoIA). As an effort in this direction, we focus on the use of object-oriented ontology modeling as an effective way of representing and enforcing the given common set of requirements established by CC. Our methodology leverages novel techniques from software requirement engineering and knowledge engineering. This paper also describes how this methodology can effectively realize CC-related requirements of the target systems and help evaluate such systems for conformance to the certification and accreditation (C&A) process.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
Carroll, J. J., Dickinson, I., Dollin, C., Reynolds, D., Seaborne, A., Jena: Implementing the Semantic Web Recommendations, Kevin Wilkinson Digital Media Systems Laboratory HP Laboratories Bristol, 2003
 
3
CC ToolBox#8482;. Developed by SPARTA, Inc. for the National Information Assurance Partnership (NIAP) http://cctoolbox.sparta.com
 
4
Common Criteria for Information Technology Security Evaluation, Part 1: Introduction and general model, Part 2: Security functional requirements, Part 3: Security assurance requirements, August 1999 Version 2.1
 
5
Hearn, J., Does the common criteria paradigm have a future?, National Cryptologic Museum, Security & Privacy Magazine, IEEE, Jan-Feb. 2004
 
6
 
7
Lee, S. W. and Yavagal, D., GenOM User's Guide, Technical Report, Department of Software and Information Systems, University of North Carolina at Charlotte, 2004
 
8
9

Collaborative Colleagues:
Deepak S. Yavagal: colleagues
Seok Won Lee: colleagues
Gail-Joon Ahn: colleagues
Robin A. Gandhi: colleagues