INFORMATION-SYSTEMS SECURITY DESIGN METHODS - IMPLICATIONS FOR INFORMATION-SYSTEMS DEVELOPMENT

被引:155
作者
BASKERVILLE, R
机构
[1] School of Management, Binghamton Uruuerszty, Binghamton
关键词
MANAGEMENT; SECURITY; CHECKLISTS; CONTROL; INTEGRITY; RISK ANALYSIS; SAFETY; STRUCTURED SYSTEMS ANALYSIS AND DESIGN; SYSTEM MODELING;
D O I
10.1145/162124.162127
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The security of information systems is a serious issue because computer abuse is increasing. It is important, therefore, that systems analysts and designers develop expertise in methods for specifying information systems security. The characteristics found in three generations of general information system design methods provide a framework for comparing and understanding current security design methods. These methods include approaches that use checklists of controls, divide functional requirements into engineering partitions, and create abstract models of both the problem and the solution. Comparisons and contrasts reveal that advances in security methods lag behind advances in general systems development methods. This analysis also reveals that more general methods fail to consider security specifications rigorously.
引用
收藏
页码:375 / 414
页数:40
相关论文
共 114 条
[1]  
AGRESTI WW, 1986, NEW PARADIGMS SOFTWA, P6
[2]  
[Anonymous], 1989, MODERN STRUCTURED AN
[3]   INFORMATION-SYSTEMS DEVELOPMENT RESEARCH - AN EXPLORATION OF IDEAS IN PRACTICE [J].
AVISON, DE ;
WOODHARPER, AT .
COMPUTER JOURNAL, 1991, 34 (02) :98-112
[4]  
AVISON DE, 1988, INFORMATION SYSTEMS
[5]  
Badenhorst K. P., 1990, Computers & Security, V9, P339, DOI 10.1016/0167-4048(90)90104-2
[6]  
BANNON L, 1989, SYSTEMS DEV HUMAN PR, P257
[7]   A REAPPRAISAL OF STRUCTURED ANALYSIS - DESIGN IN AN ORGANIZATIONAL CONTEXT [J].
BANSLER, JP ;
BODKER, K .
ACM TRANSACTIONS ON INFORMATION SYSTEMS, 1993, 11 (02) :165-193
[8]  
Baskerville R., 1991, Computers & Security, V10, P749, DOI 10.1016/0167-4048(91)90094-T
[9]  
BASKERVILLE R, 1988, DESIGNING INFORMATON
[10]  
Baskerville R, 1992, J MANAGEMENT SYSTEMS, V4, P1