Semiformal Common Criteria compliant it security development framework
Andrzej Białas · 2013
The monograph presents an IT Security Development Framework (ITSDF) based on the Common Criteria (ISO/IEC 15408) family of standards for the product designers and evaluators. The system, compliant with ISO/IEC TR 15446, is based on the enhanced generics, advanced functionality, recent information security management standards, and risk analysis. The concept presented in the monograph, dealing with the elaboration of the ITSDF framework, encompasses two basic issues: - creating the means to build the security specifications; the means include defined enhanced generics and Common Criteria components for any stage of IT security development, i.e.: security problem definition, elaborating security objectives, requirements and functions, - workout of the semiformal (UML/OCL-based) model of this development process, encompassing a data model and processes responsible for the issuing of the security specifications. Using the UML/OCL-based framework presented there, a computer-aided tool was developed (ITSDF-tool). The main goal of creating this tool is to make the IT security developers’ activities easier and more effective. Due to the semiformal character of the Common Criteria and the UML methodologies, the framework presented there has a semiformal character as well. The formal method elements were introduced in the selected areas of this framework where they can bring real advantages, especially to improve the specification means.