We present a security engineering process based on security problem frames and concretized security problem frames. Both kinds of frames constitute patterns for analyzing security problems and associated solution approaches. They are arranged in a pattern system that makes dependencies between them explicit. We describe step-by-step how the pattern system can be used to analyze a given security problem and how solution approaches can be found. Further, we introduce a new frame that focuses on the privacy requirement anonymity.
Citation:
Denis Hatebur, Maritta Heisel, Holger Schmidt, "A Security Engineering Process based on Patterns," dexa, pp.734-738, 18th International Conference on Database and Expert Systems Applications (DEXA 2007), 2007