2.6.3 Security Engineering Awareness for Systems Engineers
Sarah A. Sheard, Assad Moini · INCOSE International Symposium · 2003
Abstract Systems engineers generally are not trained in computer systems security, and those who are trained often have limited exposure to narrow areas of computer security. The result is that system‐wide security requirements often are not understood or addressed adequately, and delivered systems may contain hidden security flaws and vulnerabilities that are later exploited. Reactive efforts to patch or harden system security later in the system lifecycle are very costly and only can address flaws and vulnerabilities after they have been discovered. Given both the explosive growth of the Internet and our ever‐increasing reliance on critical information infrastructure, it is no longer sufficient for systems engineers to remain technically naïve about security considerations. This paper discusses some of the reasons for this new urgency; the areas where knowledge of computer systems security is important to systems engineers; and some topics that must be considered when eliciting, analyzing, and specifying system‐wide security requirements.