Authors:
Haralambos Mouratidis
1
;
Paolo Giorgini
2
and
Gordon Manson
3
Affiliations:
1
School of Computing and Technology, University of East London, United Kingdom
;
2
University of Trento, Italy
;
3
University of Sheffield, United Kingdom
Keyword(s):
Information Systems Analysis, Systems Engineering Methodologies, Security, Scenarios
Related
Ontology
Subjects/Areas/Topics:
Enterprise Information Systems
;
Formal Methods
;
Information Engineering Methodologies
;
Information Systems Analysis and Specification
;
Methodologies and Technologies
;
Methodologies, Processes and Platforms
;
Model-Driven Software Development
;
Operational Research
;
Security
;
Simulation and Modeling
;
Software Engineering
;
Systems Engineering
Abstract:
It has been widely argued in the literature that security concerns should be integrated with software engineering practices. However, only recently work has been initiated towards this direction. Most of this work, however, only considers how security can be analysed during the development lifecycles and not how the security of an information system can be tested during the analysis and design stages. In this paper we present results from the development of a technique, which is based on the use of scenarios, to test the reaction of an information system against potential security attacks.