Model-Based Risk Assessment in a Component-Based Software Engineering Process The CORAS Approach to IdentifY Security Risks

Ketil St, Folker den Braber, Theo Dimitrakos, Rune Fredriksen, Axel Gran, Siv Hilde Houmb, Yannis C. Stamatiou · 2003

The EU-funded CORAS project (lST-2000-25031) is developing a framework for model-based risk assessment of security-critical systems. This framework is characterised by: (I) A careful integration of techniques and features from partly complementary risk assessment methods. (2) Patterns and methodology for UML oriented modelling targeting the different risk assessment methods. (3) A risk management process based on ASINZS 4360. (4) A risk documentation framework based on RM-ODP. (5) An integrated risk management and system development process based on UP. (6) A platform for tool-inclusion based on XML. This chapter describes and explains the CORAS approach to model­ based risk assessment. The ability to aid risk assessment in a component-based software engineering process receives particular attention. We consider maintenance, composition as well as reuse of risk assessment results.

Read the paper · More papers on PaperTik