Security Systems Engineering

Stuart Jacobs · 2011

A security management program can be assisted by several well-known security practices and guidelines, namely the international standards ISO 27001 and ISO 27002. Security engineering begins with an understanding of the operational environment within which the enterprise operates and the specific security related objectives of the organization. The process of requirements decomposition begins with an analysis of the enterprise security policy and what it requires from a functional perspective. The chapter discusses the access control and access control structures, and also discusses the simple mathematical structures and their use in access control. A key component of security systems engineering includes selection or development of a security model to describe the entities governed by the security policy, and define the rules that govern this policy. Much of the current work on security occurs within Standards Development Organizations (SDOs). Controlled Vocabulary Terms access control; ISO standards; security

Read the paper · More papers on PaperTik