Secure Software Education: A Contextual Model-Based Approach
نویسندگان
چکیده
This article establishes a context for secure information systems development as well as a set of models used to develop and apply a secure software production pedagogy. A generic system model is presented to support the system context development, and to provide a framework for discussing security relationships that exist between and among information systems and their applications. An asset protection model is tailored to provide a conceptual ontology for secure information system topics, and a stable logical framework that is independent of specific organizations, technologies and their associated changes. This asset protection model provides a unique focus for each of the three primary professional communities associated with the development and operation of secure information systems: the systems/software engineering, information assurance, and the legal/justice/intelligence communities. It is also a vehicle for structured interfaces among these groups. A secure adaptive response model is discussed to provide an analytical tool to assess risk associated with the development and deployment of secure information systems and a security metric with which to determine coverage of topics to address and mitigate those risks. A pedagogical model for information assurance curriculum development is then established in the context and terms of the developed secure information system models. The relevance of secure coding techniques to the production of secure systems, architectures and organizational operations is also discussed.
منابع مشابه
Mapping of McGraw Cycle to RUP Methodology for Secure Software Developing
Designing a secure software is one of the major phases in developing a robust software. The McGraw life cycle, as one of the well-known software security development approaches, implements different touch points as a collection of software security practices. Each touch point includes explicit instructions for applying security in terms of design, coding, measurement, and maintenance of softwar...
متن کاملDesigning and Validating the Service-Oriented University Model from the Standpoint of Higher Education Experts
Service orientation is a pivotal factor and a strategic direction for the university to keep with changes and perceptions of social needs. Accordingly, the main purpose of this study is to develop a model for the service-oriented university within the framework of service provision to the community. This research was conducted using a qualitative approach based on the grounded theory method. Th...
متن کاملDesigning a social responsibility curriculum model for the higher education system based on the Akker Model
The purpose of the present study was to design a curriculum based on social responsibility for the Iranian higher education system by analyzing students 'lived experiences and analyzing written and digital resources related to students' social responsibility using qualitative approach and phenomenological methods and themes analysis. In the phenomenological method, participants were 13 universi...
متن کاملThe Study of the Convergence of University Governance and Quasi-Market Actions in Iran's Higher Education
In recent years, due to the emergence of new ideas such as the new public management approach, knowledge-based societies and economies, and globalization, the concepts of efficiency, effectiveness, and accountability in the public sector have attracted more attention to themselves. In this regard, Higher education in Iran has been influenced by the upstream documents, to shift its governance ap...
متن کاملDesigning a Citizenship Education Curriculum Model for Students with Special Needs (Mentally Retarded)
The purpose of this study was to design a citizenship education curriculum model for students with special needs.The qualitative methodology of the data theory of the foundation is used and in terms of research philosophy. It is in the category of applied positivist paradigm and in terms of qualitative and quantitative research, it has an inductive and deductive approach and survey strategy. Th...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- IJSSE
دوره 1 شماره
صفحات -
تاریخ انتشار 2010