Risk Expectation Management for Building Secure Information Systems

Donald M. Howe · INCOSE International Symposium · 1993

Abstract This paper describes the process of building Information Systems that integrate security mechanisms to protect from unauthorized access and mistreatment Risk expectation management for information systems is associated with security requirements‐policy‐architecture‐risk analysis and synthesis. Cognizance of threat is the most important part of developing secure information systems. The paper organizes the complexity of information security principles into a structured approach intended to minimize the expected security risk. An example is presented in the appendix.

Read the paper · More papers on PaperTik