Authors:
Jingde Cheng
;
Yuichi Goto
and
Daisuke Horie
Affiliation:
Saitama University, Japan
Keyword(s):
Security engineering, Information security engineering environment, ISO/IEC security standards, Formal methods.
Related
Ontology
Subjects/Areas/Topics:
Information and Systems Security
;
Secure Software Development Methodologies
;
Security Deployment
;
Security Engineering
;
Security in Information Systems
;
Security Verification and Validation
Abstract:
Security Engineering has some features that are intrinsically different from Software (Reliability) Engineering. Traditional software engineering environments are not adequate and effective for designing, developing, managing, and maintaining secure software systems. This position paper presents ISEE, an information security engineering environment we are developing, that integrates various tools and provides comprehensive facilities to support design, development, management, and maintenance of security facilities of information/software systems continuously and consistently, and guides and helps all users to perform their tasks regularly according to ISO/IEC security standards. The paper presents the basic ideas on development of ISEE, basic requirements for ISEE, and a design of ISEE. ISEE is the first real information security engineering environment.