OTPAF: A Security Requirement Conceptual Model of SaaS for Malaysian Government based on Common Criteria

Norlaili binti Abdul Hamid, I. Mohamed, Maslina Daud, Norahana Salimin, N. I. Ahmad
{"title":"OTPAF: A Security Requirement Conceptual Model of SaaS for Malaysian Government based on Common Criteria","authors":"Norlaili binti Abdul Hamid, I. Mohamed, Maslina Daud, Norahana Salimin, N. I. Ahmad","doi":"10.1109/ICEEI47359.2019.8988832","DOIUrl":null,"url":null,"abstract":"The aim of this study is to define security requirements (SR) of Information Technology (IT) product that is deployed on Cloud platform as Software as a Service (SaaS) for Malaysian government. This is critical in order to secure the product from information security threats such as malware attack, account hijacking, data leakage and at the same time, in line with government policy. It is important to address the SR as early as before the product acquisition to avoid any security incidents happen that will affect the government IT ecosystem. Hence, to help government officer from IT and procurement department in preparing security specification for acquisition or procurement exercise, we introduce OTPAF model, a novel approach for defining SR by connecting security components which are security objective (O), threat (T), policy (P), assumption (A) and functionality (F) in deriving a relational statement. First we acquire the government information security objectives and policies. Then cloud top threats and controls are referred to map altogether. Following that, we elicit the security functionality using Common Criteria (CC) approach and combines the components to become SR. Result presents how the conceptual model OTPAF and the values of the security components deriving to a relational statement that becoming SR.","PeriodicalId":236517,"journal":{"name":"2019 International Conference on Electrical Engineering and Informatics (ICEEI)","volume":"91 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 International Conference on Electrical Engineering and Informatics (ICEEI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICEEI47359.2019.8988832","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The aim of this study is to define security requirements (SR) of Information Technology (IT) product that is deployed on Cloud platform as Software as a Service (SaaS) for Malaysian government. This is critical in order to secure the product from information security threats such as malware attack, account hijacking, data leakage and at the same time, in line with government policy. It is important to address the SR as early as before the product acquisition to avoid any security incidents happen that will affect the government IT ecosystem. Hence, to help government officer from IT and procurement department in preparing security specification for acquisition or procurement exercise, we introduce OTPAF model, a novel approach for defining SR by connecting security components which are security objective (O), threat (T), policy (P), assumption (A) and functionality (F) in deriving a relational statement. First we acquire the government information security objectives and policies. Then cloud top threats and controls are referred to map altogether. Following that, we elicit the security functionality using Common Criteria (CC) approach and combines the components to become SR. Result presents how the conceptual model OTPAF and the values of the security components deriving to a relational statement that becoming SR.
OTPAF:基于通用标准的马来西亚政府SaaS安全需求概念模型
本研究的目的是为马来西亚政府定义部署在云平台上的信息技术(IT)产品的安全要求(SR)作为软件即服务(SaaS)。这对于保护产品免受恶意软件攻击、账户劫持、数据泄露等信息安全威胁至关重要,同时也符合政府政策。重要的是在产品采购之前尽早解决SR问题,以避免发生任何影响政府It生态系统的安全事件。因此,为了帮助IT和采购部门的政府官员为采购或采购工作准备安全规范,我们引入了OTPAF模型,这是一种通过连接安全组件来定义SR的新方法,这些组件是安全目标(O)、威胁(T)、政策(P)、假设(a)和功能(F),从而得出关系声明。首先我们了解政府信息安全的目标和政策。然后将云顶威胁和控制统称为地图。接下来,我们使用通用标准(CC)方法引出安全功能,并将组件组合为SR。结果展示了OTPAF概念模型和安全组件的值如何派生为成为SR的关系语句。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信