Using UML in a Risk-Driven Development Process

نویسندگان

  • Siv Hilde Houmb
  • Ørjan Markhus Lillevik
چکیده

Risk-driven development focus on identifying and treating risks as an integrated part of the development process. One then obtain an adequate security level by treating security issues at the right time for the correct cost throughout the development. The EU IST-project CORAS has developed an integrate risk management and system development process for security-critical systems based on AS/NZS 4360, RUP, and RM–ODP. However, trials have shown that the efficiency and applicability of the integrated process depends on having an experienced risk analyst present during development. In this paper we present a refinement of the context identification phase of CORAS and provide detailed description on how to employ UML according to each of the RM– ODP viewpoints in each phase of the development. The refinements are described through a set of guidelines that where developed applying the CORAS integrated process on an example system. These guidelines reflects the experiences gained in a set of trials performed within the CORAS project.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Aspect Oriented UML to ECORE Model Transformation

With the emerging concept of model transformation, information can be extracted from one or more source models to produce the target models. The conversion of these models can be done automatically with specific transformation languages. This conversion requires mapping between both models with the help of dynamic hash tables. Hash tables store reference links between the elements of the source...

متن کامل

Applying Model-Driven Development to Business Systems using RM-ODP and EDOC

Improving development efficiency and maintainability for business systems requires a seamless development process, and both RM-ODP and MDA play a key role to this end. This paper shows our Model-Driven Development process in building business systems using RM-ODP and UML Profile for EDOC, with a case study of Electronic Health Record system models, and discusses several issues related to RM-ODP...

متن کامل

Risk-Driven Development Of Security-Critical Systems Using UMLsec

Despite a growing awareness of security issues in distributed computing systems, most development processes used today still do not take security aspects into account. To address this problem we make use of a risk-driven approach to develop security-critical systems based on UMLsec, the extension of the Unified Modeling Language (UML) for secure systems development, the safety standard ICE 6150...

متن کامل

Extending Security Requirement Patterns to Support Aspect-Oriented Risk-Driven Development

This paper presents a pattern representation of security concern solutions and their interactions that support aspect-oriented risk-driven development (AORDD). Security concern solutions are specified early in the development process, using UML as a rigorous notation for sets of patterns. A profile consisting of stereotypes and tagged values supports security concern requirement traceability th...

متن کامل

Experiences from Model-Driven Development of Homecare Services: UML Profiles and Domain Models

Model-driven development approaches such as OMG’s Model Driven Architecture (MDA) have been proposed as the new paradigm for software development. However, the adoption of MDA is still low, partly because of the general-purpose modelling language being used. Domain specific modelling languages are being developed for technological and industrial domains to improve the expressiveness and effect ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2004