Validation of the Specification Means Ontology on the Simple Firewall Case.
Andrzej Białas · Security and Management · 2009
The paper concerns the validation of the new Specification Means Ontology (SMO) elaborated by the author. The SMO provides the specification means for the IT security development process compliant with the Common Criteria standard, i.e. to specify threats, assumptions, organizational security policies, security objectives, requirements and functions, as well as evidences, elaborated during the TOE development process. The extensive SMO and the knowledge base related to the specification means need to be validated on different kinds of projects, reflecting different requirements and expectations of the developers. The paper presents the results of the case study focused on the simple firewall example. The paper features strong and weak points of this proposed ontology-based IT security development methodology.