Catalog of security tactics linked to common criteria requirements

Christopher Preschern · 2012

Security tactics describe security design decisions in a very general, abstract, and implementation-independent way and provide basic security design guidance. Tactics directly address system quality attributes and can be seen as building blocks for design patterns. In order to establish a more detailed security tactic collection, we link them with the Common Criteria security certification standard by establishing a connection between the security tactic goals and the Common Criteria Security Functional Requirements through Goal Structuring Notation. In this paper we give a brief introduction to the Common Criteria standard and to Goal Structuring Notation, we present the full structured and refined catalog of security tactics, and we discuss benefits of the link with the Common Criteria security standard regarding security certification.

Read the paper · More papers on PaperTik