A Business Process-based Method on Security Requirement Analysis of Information Systems

Yu Zhiwei,Tang Rengzhong,Jia Dongjiao,Ye Fanbo
DOI: https://doi.org/10.3321/j.issn:1004-132X.2007.04.021
2007-01-01
Abstract:To identify the security requirements of information systems, a business process-based security requirement analysis method was presented. Focused on the business process security, the related assets which affect the business process security were identified by security tree model. The security requirements of assets were identified by risk packet and risk transferring model, and then the security requirements list was formed after coverage analysis. Finally, a case was studied to illustrate the proposed method.
What problem does this paper attempt to address?