ESRML: a markup language for enterprise security requirement specification
J. Roy, Mridul Sankar Barik, Chandan Mazumdar · 2005
Every enterprise needs to monitor its computing system for possible unauthorized intrusion and other attacks and these activities should be part of its daily routine to safeguard enterprise information system. The ISO 17799 best practices for information security management specifically addresses these issues and provides detailed guidelines on how a secure management framework should be implemented. To capture the security requirements of an organization properly, a customized information security specification language is needed. This paper presents an XML based structured language ESRML (enterprise security requirement markup language) for specifying enterprise information security requirement conforming the ISO 17799 standard.