Secure Software Education: A Contextual Model-Based Approach

J. Simpson, M. Simpson, B. Endicott-Popovsky, Viatcheslav Popovsky
{"title":"Secure Software Education: A Contextual Model-Based Approach","authors":"J. Simpson, M. Simpson, B. Endicott-Popovsky, Viatcheslav Popovsky","doi":"10.4018/JSSE.2010100103","DOIUrl":null,"url":null,"abstract":"This article establishes a context for secure information systems development as well as a set of models used to develop and apply a secure software production pedagogy. A generic system model is presented to support the system context development, and to provide a framework for discussing security relationships that exist between and among information systems and their applications. An asset protection model is tailored to provide a conceptual ontology for secure information system topics, and a stable logical framework that is independent of specific organizations, technologies, and their associated changes. This asset protection model provides a unique focus for each of the three primary professional communities associated with the development and operation of secure information systems. In this paper, a secure adaptive response model is discussed to provide an analytical tool to assess risk associated with the development and deployment of secure information systems, and to use as a security metric. A pedagogical model for information assurance curriculum development is then established in the context and terms of the developed secure information system models. The relevance of secure coding techniques to the production of secure systems, architectures, and organizational operations is also discussed.","PeriodicalId":89158,"journal":{"name":"International journal of secure software engineering","volume":"116 1","pages":"35-61"},"PeriodicalIF":0.0000,"publicationDate":"2010-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal of secure software engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/JSSE.2010100103","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

This article establishes a context for secure information systems development as well as a set of models used to develop and apply a secure software production pedagogy. A generic system model is presented to support the system context development, and to provide a framework for discussing security relationships that exist between and among information systems and their applications. An asset protection model is tailored to provide a conceptual ontology for secure information system topics, and a stable logical framework that is independent of specific organizations, technologies, and their associated changes. This asset protection model provides a unique focus for each of the three primary professional communities associated with the development and operation of secure information systems. In this paper, a secure adaptive response model is discussed to provide an analytical tool to assess risk associated with the development and deployment of secure information systems, and to use as a security metric. A pedagogical model for information assurance curriculum development is then established in the context and terms of the developed secure information system models. The relevance of secure coding techniques to the production of secure systems, architectures, and organizational operations is also discussed.
安全软件教育:基于上下文模型的方法
本文建立了安全信息系统开发的上下文,以及用于开发和应用安全软件生产教学法的一组模型。提出了一个通用的系统模型来支持系统上下文的开发,并为讨论信息系统及其应用程序之间存在的安全关系提供了一个框架。资产保护模型旨在为安全信息系统主题提供概念本体,以及独立于特定组织、技术及其相关变更的稳定逻辑框架。这种资产保护模型为与安全信息系统的开发和操作相关的三个主要专业社区中的每一个提供了独特的焦点。本文讨论了一种安全自适应响应模型,以提供一种分析工具来评估与安全信息系统的开发和部署相关的风险,并将其用作安全度量。然后在已开发的安全信息系统模型的背景和条件下,建立了信息保障课程开发的教学模型。安全编码技术对安全系统、体系结构和组织操作的生产的相关性也被讨论。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信