ENFORCING EARLY IMPLEMENTATION OF INFORMATION ASSURANCE PRECEPTS THROUGHOUT THE DESIGN PHASE

Ken Trimmer, Corey D. Schou, Kevin R. Parker · 2007

ABSTRACT Secure information systems are of great concern to organizations and governments. However, the topic of information systems security is inadequately addressed in most textbooks commonly used in Systems Analysis and Design and Database Design courses. Students do not learn the importance of information security unless supplemental materials are provided. At best, information system security is often viewed as a broad non-functional requirement and as a late-binding decision in systems design. We propose using the Reference Monitor (RM) as a conceptual framework to introduce security into Systems Analysis and Database Design courses as well as subsequent design/ implementation courses. Keywords: systems development life cycle, requirements analysis phase, design .....reference monitor, information assurance, McCumber, MSR model I. INTRODUCTION Information systems (IS) are ubiquitous and pervasive throughout society, and they are part of a critical information infrastructure (CII). A critical information infrastructure is a communications or information service whose availability, reliability and resilience is essential to the functioning of a modern economy, security, and other essential social values [Cukier, 2005]. Information systems practitioners must

Read the paper · More papers on PaperTik