4.3.2 Systems Engineering Approach To Information Assurance
Kim H. Taylor, Crystal D. Sloan · INCOSE International Symposium · 2004
Abstract Today's security solutions for protecting telecommunications and information infrastructures are primarily defensive. They are not commensurate with the increasingly sophisticated nature of the global cyberthreat, and likely ineffective in countering new, dormant threats that could be a strategic surprise to organizational security. Defensive measures such as firewall and antivirus software can only protect computer networks and systems against known signatures of malicious code. To engineer pre‐emptive capabilities and processes that discourage and repel attacks would require integration of key aspects of security domain engineering into systems engineering practices. An integrated approach would promote the implementation of security controls and processes as built‐in features of future human/computer systems and networks, rather than as separate solutions, thus enabling a more holistic and robust information assurance.