skip to main content
10.1145/3344948.3344977acmotherconferencesArticle/Chapter ViewAbstractPublication PagesecsaConference Proceedingsconference-collections
research-article

A systems-of-systems security framework for requirements definition in cloud environment

Published:09 September 2019Publication History

ABSTRACT

There are many aspects that involve the development of secure software. Regardless of the development model, the verification and validation of security must always be present, in all environments and stages. Systems-of-Systems (SoS) refer to a complex system that comprises other systems (the constituent systems), which have operational and managerial independence, geographical distribution, emergent behavior, and evolutionary development processes. By integrating cloud computing applications and services into a complex existing system, many challenges arise, especially those related to security issues. In this paper, it is proposed a security framework to guide the planning and definition phases of security requirements for SoS considering agile methods for application development and a DevSecOps approach. By using a checklist and some questions to identify which security aspects should be included, security drivers were obtained to integrate cloud computing in a SoS context, taking into account the perspectives of existing IT Governance Model, IT Operational Model, and IT Processes. Additionally, it is emphasized the need for a human resources management that aims at the positive acceptance of organizational change by all involved.

References

  1. ISO/IEC 27000:2018, Information technology - Security techniques - Information security management systems - Overview and vocabularyGoogle ScholarGoogle Scholar
  2. ISO/IEC 27001:2013, Information technology - Security techniques - Information security management systems - RequirementsGoogle ScholarGoogle Scholar
  3. M. P. Correia and P. J. Sousa. 2017. Secure Software. (2nd. ed.). ISBN-13: 9789727228584Google ScholarGoogle Scholar
  4. Systems Security Engineering - Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems. NIST Special Publication 800-160. Updated March 2018.Google ScholarGoogle Scholar
  5. INCOSE Systems Engineering Handbook, 4th Edition, John Wiley & Sons Inc., 2015Google ScholarGoogle Scholar
  6. A. Habl, O. Kipouridis and J. Fottner, "Deploying microservices for a cloud-based design of system-of-systems in intralogistics", IEEE 15th International Conference on Industrial Informatics (INDIN), July 2017, Emden, GermanyGoogle ScholarGoogle ScholarCross RefCross Ref
  7. L. Riungu-Kalliosaari, L. E. Lwakatare and S. Makinen T. Männistö. DevOps Adoption Benefits and Challenges in Practice: A Case Study. Product-Focused Software Process Improvement: 17th International Conference, PROFES 2016, Trondheim, Norway, November 22--24, 2016, Proceedings (pp.590--597).Google ScholarGoogle Scholar
  8. ISO/IEC 27017:2015, Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud servicesGoogle ScholarGoogle Scholar
  9. Project Management Institute (PMI) - PMBOK® Guide. A Guide to the Project Management Body of Knowledge, 6th. ed., 2017.Google ScholarGoogle Scholar
  10. H. Kezner, "Project Management: A Systems Approach to Planning, Scheduling and Controlling", 12th. ed., Wiley, 2017.Google ScholarGoogle Scholar
  11. M. Rokeach. The nature of human values. 1973. New York, NY. The Free Press.Google ScholarGoogle Scholar
  12. M. Rokeach. Understanding human values - Individual and Societal.2008.New York, NY. The Free Press.Google ScholarGoogle Scholar
  13. R. A. Noe, J. R. Hollenbeck, B. Gerhart and P. M. Wright. Human resource management: Gaining a competitive advantage. 2017.Google ScholarGoogle Scholar
  14. P. Boxall and J. Purcell. Strategy and Human Resource Management. 3rd. ed., 2011.Google ScholarGoogle Scholar
  15. S. H. Schwartz. An Overview of the Schwartz Theory of Basic Values. Online Readings in Psychology and Culture. 2012.Google ScholarGoogle Scholar
  16. S. H. Schwartz. Universals in the Content and Structure of Values: Theoretical Advances and Empirical Tests in 20 Countries, Advances in Experimental Social Psychology Vol. 25, Elsevier, pp. 1--65Google ScholarGoogle Scholar

Recommendations

Comments

Login options

Check if you have access through your login credentials or your institution to get full access on this article.

Sign in
  • Published in

    cover image ACM Other conferences
    ECSA '19: Proceedings of the 13th European Conference on Software Architecture - Volume 2
    September 2019
    286 pages
    ISBN:9781450371421
    DOI:10.1145/3344948

    Copyright © 2019 ACM

    Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    • Published: 9 September 2019

    Permissions

    Request permissions about this article.

    Request Permissions

    Check for updates

    Qualifiers

    • research-article

    Acceptance Rates

    ECSA '19 Paper Acceptance Rate48of72submissions,67%Overall Acceptance Rate48of72submissions,67%

PDF Format

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader