| Common criteria requirements modeling and its uses for quality of information assurance (QoIA) |
| Full text |
Pdf
(563 KB)
|
| Source
|
ACM Southeast Regional Conference
archive
Proceedings of the 43rd annual Southeast regional conference - Volume 2
table of contents
Kennesaw, Georgia
SESSION: Security
table of contents
Pages: 130 - 135
Year of Publication: 2005
ISBN:1-59593-059-0
|
|
Authors
|
|
Deepak S. Yavagal
|
The University of North Carolina at Charlotte, Charlotte, NC
|
|
Seok Won Lee
|
The University of North Carolina at Charlotte, Charlotte, NC
|
|
Gail-Joon Ahn
|
The University of North Carolina at Charlotte, Charlotte, NC
|
|
Robin A. Gandhi
|
The University of North Carolina at Charlotte, Charlotte, NC
|
|
| Sponsor |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 25, Downloads (12 Months): 125, Citation Count: 0
|
|
|
ABSTRACT
The Common Criteria for Information Technology Security Evaluation (CCITSE), usually referred to as the Common Criteria (CC), establishes a level of trustworthiness and confidence that should be placed in the security functions of products or systems and the assurance measures applied to them. CC achieves this by evaluating the product or system conformance with a common set of requirements set forth by it. To engineer a product that meets the information assurance goals of CC, a structured and comprehensive methodology is required to drive the activities undertaken in all the stages of the software requirements engineering (RE) process. Such a methodology is inevitable to understand and attain the Quality of Information Assurance (QoIA). As an effort in this direction, we focus on the use of object-oriented ontology modeling as an effective way of representing and enforcing the given common set of requirements established by CC. Our methodology leverages novel techniques from software requirement engineering and knowledge engineering. This paper also describes how this methodology can effectively realize CC-related requirements of the target systems and help evaluate such systems for conformance to the certification and accreditation (C&A) process.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
| |
2
|
Carroll, J. J., Dickinson, I., Dollin, C., Reynolds, D., Seaborne, A., Jena: Implementing the Semantic Web Recommendations, Kevin Wilkinson Digital Media Systems Laboratory HP Laboratories Bristol, 2003
|
| |
3
|
CC ToolBox#8482;. Developed by SPARTA, Inc. for the National Information Assurance Partnership (NIAP) http://cctoolbox.sparta.com
|
| |
4
|
Common Criteria for Information Technology Security Evaluation, Part 1: Introduction and general model, Part 2: Security functional requirements, Part 3: Security assurance requirements, August 1999 Version 2.1
|
| |
5
|
Hearn, J., Does the common criteria paradigm have a future?, National Cryptologic Museum, Security & Privacy Magazine, IEEE, Jan-Feb. 2004
|
| |
6
|
|
| |
7
|
Lee, S. W. and Yavagal, D., GenOM User's Guide, Technical Report, Department of Software and Information Systems, University of North Carolina at Charlotte, 2004
|
| |
8
|
|
 |
9
|
|
|