Skip to main content

2018 | OriginalPaper | Buchkapitel

5. Introducing CAIRIS: Tool-Support for Designing Usable and Secure Systems

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

This chapter presents CAIRIS (Computer Aided Integration of Requirements and Information Security): a software platform designed to embody the characteristics needed to support the IRIS framework. I introduce the design principles that guided the development of CAIRIS in Sect. 5.1, before briefly describing how the platform was developed in Sect. 5.2. The design of CAIRIS is then reviewed in terms of its high level architecture, physical deployment, and visual layout in Sect. 5.3, before describing how the platform’s characteristics satisfy the design principles we wish to foster in Sect. 5.4.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Shneiderman B. The eyes have it: a task by data type taxonomy for information visualizations. In: VL ’96: Proceedings of the 1996 IEEE symposium on visual languages. USA: IEEE Computer Society; 1996. p. 336. Shneiderman B. The eyes have it: a task by data type taxonomy for information visualizations. In: VL ’96: Proceedings of the 1996 IEEE symposium on visual languages. USA: IEEE Computer Society; 1996. p. 336.
9.
Zurück zum Zitat Faily S. Integrating Requirements and Risk Management to analyse contexts of use, Oxford University Computing Laboratory Cake Seminar. Oxford: UK (Oral Presentation); 2009. Faily S. Integrating Requirements and Risk Management to analyse contexts of use, Oxford University Computing Laboratory Cake Seminar. Oxford: UK (Oral Presentation); 2009.
10.
Zurück zum Zitat Faily S. Integrating Requirements and Information Security, BCS Requirements Engineering Specialist Group Postgraduate Workshop. London: UK (Oral Presentation); 2009. Faily S. Integrating Requirements and Information Security, BCS Requirements Engineering Specialist Group Postgraduate Workshop. London: UK (Oral Presentation); 2009.
11.
Zurück zum Zitat Wilder B. Cloud architecture patterns. O’Reilly; 2012. Wilder B. Cloud architecture patterns. O’Reilly; 2012.
12.
Zurück zum Zitat Reenskaug T. Models-views-controllers. Xerox Palo Alto Research Center; 1979. Reenskaug T. Models-views-controllers. Xerox Palo Alto Research Center; 1979.
14.
Zurück zum Zitat Noessel C, Cooper A, Reimann R, Cronin D. About face: the essentials of interaction design. 4th ed. John Wiley & Sons; 2014. Noessel C, Cooper A, Reimann R, Cronin D. About face: the essentials of interaction design. 4th ed. John Wiley & Sons; 2014.
15.
Zurück zum Zitat Faily S. Towards requirements engineering practice for professional end user developers: a case study. In: Proceedings of the 3rd international workshop on requirements engineering education and training. IEEE Computer Society; 2008. p. 38–44. Faily S. Towards requirements engineering practice for professional end user developers: a case study. In: Proceedings of the 3rd international workshop on requirements engineering education and training. IEEE Computer Society; 2008. p. 38–44.
17.
Zurück zum Zitat Gamma E, Helm R, Johnson R, Vlissides J. Design patterns: elements of reusable object-oriented software. Addison-Wesley; 1995. Gamma E, Helm R, Johnson R, Vlissides J. Design patterns: elements of reusable object-oriented software. Addison-Wesley; 1995.
18.
Zurück zum Zitat ISO. ISO 9241–11. Ergonomic requirements for office work with visual display terminals (VDT)s - Part 11 Guidance on usability; 1998. ISO. ISO 9241–11. Ergonomic requirements for office work with visual display terminals (VDT)s - Part 11 Guidance on usability; 1998.
19.
Zurück zum Zitat IEC. IEC 61508: Functional safety of electrical/electronic/programmable electronic safety-related systems. Parts 1–7. Switzerland: International Electrotechnical Commission; 1998–2005. IEC. IEC 61508: Functional safety of electrical/electronic/programmable electronic safety-related systems. Parts 1–7. Switzerland: International Electrotechnical Commission; 1998–2005.
20.
Zurück zum Zitat Tufte ER. Envisioning information. Graphics Press; 1990. Tufte ER. Envisioning information. Graphics Press; 1990.
21.
Zurück zum Zitat Chernoff H. The Use of Faces to Represent Points in K-Dimensional Space Graphically. J Am Stat Assoc. 1973;68. Chernoff H. The Use of Faces to Represent Points in K-Dimensional Space Graphically. J Am Stat Assoc. 1973;68.
23.
Zurück zum Zitat Tufte ER. Visual explanations: images and quantities, evidence and narrative. Graphics Press; 1997. Tufte ER. Visual explanations: images and quantities, evidence and narrative. Graphics Press; 1997.
24.
Zurück zum Zitat den Braber F, Hogganvik I, Lund MS, Stølen K, Vraalsen F. Model-based security analysis in seven steps - A guided tour to the CORAS method. BT Technol J. 2007;25(1):101–17. den Braber F, Hogganvik I, Lund MS, Stølen K, Vraalsen F. Model-based security analysis in seven steps - A guided tour to the CORAS method. BT Technol J. 2007;25(1):101–17.
25.
Zurück zum Zitat Fléchais I. Designing Secure and Usable Systems. University College London; 2005. Fléchais I. Designing Secure and Usable Systems. University College London; 2005.
27.
Zurück zum Zitat National institute of standards and technology. system protection profile - Industrial control systems v1.0. Gaithersburg, Maryland: National Institute of Standards and Technology; 2004. National institute of standards and technology. system protection profile - Industrial control systems v1.0. Gaithersburg, Maryland: National Institute of Standards and Technology; 2004.
Metadaten
Titel
Introducing CAIRIS: Tool-Support for Designing Usable and Secure Systems
verfasst von
Shamal Faily
Copyright-Jahr
2018
DOI
https://doi.org/10.1007/978-3-319-75493-2_5

Premium Partner