par Massacci, Fabio;Bouquet, Fabrice;Fourneret, Elizabeta;Jurjens, Jan;Lund, Mass S.;Madelénat, Sébastien;Mühlberg, Jan Tobias ;Paci, Federica;Paul, Stéphane;Piessens, Frank;Solhaug, Bjornar;Wenzel, Sven
Référence 4th European Conference, ServiceWave 2011(October 26-28, 2011: Poznan, Poland), Towards a Service-Based Internet, Lecture notes in computer science (6994)
Publication Publié, 2011
Publication dans des actes
Résumé : How to design a security engineering process that can cope with the dynamic evolution of Future Internet scenarios and the rigidity of existing system engineering processes? The SecureChange approach is to orchestrate (as opposed to integrate) security and system engineering concerns by two types of relations between engineering processes: (i) vertical relations between successive security-related processes; and (ii) horizontal relations between mainstream system engineering processes and concurrent security-related processes. This approach can be extended to cover the complete system/ software lifecycle, from early security requirement elicitation to runtime configuration and monitoring, via high-level architecting, detailed design, development, integration and design-time testing. In this paper we illustrate the high-level scientific principles of the approach.