首页    期刊浏览 2025年08月16日 星期六
登录注册

文章基本信息

  • 标题:Specification of security environment of IT security-related products according to Common Criteria
  • 本地全文:下载
  • 作者:ANDRZEJ BIA�?AS
  • 期刊名称:Theoretical and Applied Informatics
  • 印刷版ISSN:1896-5334
  • 出版年度:2006
  • 卷号:18
  • 期号:2
  • 页码:141-157
  • 出版社:Versita Open
  • 摘要:

    The paper concerns IT security development and evaluation processes according to the Common Criteria – CC (ISO/IEC 15408) family of standards, and is based on the results of the au-thor’s earlier works dealing with modelling of these processes. The paper focuses on the workout of the security environment specification based on the previously identified features of an IT security-related product, presented in [2]. The security environment presents the nature and scope of the IT security-related product and discusses the threats, policy rules and assumptions of the product working environment. This specification is used for the security objectives definition, which is the basis for further IT security development stages. The UML-based approach was introduced to specify the secu-rity environment using predefined generics contained within the design library. It is part of the com-mon development framework and a computer-aided tool developed on the framework. Using the UML in the Common Criteria based IT security development process allows achieving more consistent designs in an easier way.

  • 关键词:Common Criteria; IT security; design; evaluation; development; computer-aiding; secu-rity engineering; UML; modelling.
国家哲学社会科学文献中心版权所有