Socio-technical systems are an interplay of social (humans and organizations) and technical components interacting with one another to achieve their objectives. Security is a central issue in such complex systems, and it cannot be tackled only through technical mechanisms: the encryption of sensitive data while being transmitted, does not assure that the receiver will not disclose them to unauthorized parties. Therefore, dealing with security in socio-technical systems requires an analysis: (i) from a social and organizational perspective, to elicit the objectives and security requirements of each component; (ii) from a procedural perspective, to define how the actors behave and interact with each other. But, socio-technical systems need to adapt to changes of the external environment, making the need to deal with security a problem that has to be faced during all the systems’ life-cycle. We propose an iterative and incremental process to elicit security requirements and verify the socio-technical system’s compliance with such requirements throughout the systems’ life cycle.

(2014). Preserving compliance with security requirements in socio-technical systems . Retrieved from https://hdl.handle.net/10446/324068

Preserving compliance with security requirements in socio-technical systems

Salnitri, Mattia;
2014-01-01

Abstract

Socio-technical systems are an interplay of social (humans and organizations) and technical components interacting with one another to achieve their objectives. Security is a central issue in such complex systems, and it cannot be tackled only through technical mechanisms: the encryption of sensitive data while being transmitted, does not assure that the receiver will not disclose them to unauthorized parties. Therefore, dealing with security in socio-technical systems requires an analysis: (i) from a social and organizational perspective, to elicit the objectives and security requirements of each component; (ii) from a procedural perspective, to define how the actors behave and interact with each other. But, socio-technical systems need to adapt to changes of the external environment, making the need to deal with security a problem that has to be faced during all the systems’ life-cycle. We propose an iterative and incremental process to elicit security requirements and verify the socio-technical system’s compliance with such requirements throughout the systems’ life cycle.
2014
Inglese
Cyber Security and Privacy. Third Cyber Security and Privacy EU Forum, CSP Forum 2014, Athens, Greece, May 21-22, 2014, Revised Selected Papers
9783319125732
470
49
61
cartaceo
online
Switzerland
Springer
CSP Forum 2014: Third Cyber Security and Privacy EU Forum; Athens, Greece, May 21-22, 2014
3
Athens (Greece)
21/05/2014 - 22/05/2014
internazionale
contributo
Settore IINF-05/A - Sistemi di elaborazione delle informazioni
Business processes; Compliance; Security policies; Security requirements; Socio-technical systems
info:eu-repo/semantics/conferenceObject
3
Salnitri, Mattia; Paja, E.; Giorgini, P.
1.4 Contributi in atti di convegno - Contributions in conference proceedings::1.4.01 Contributi in atti di convegno - Conference presentations
reserved
Non definito
273
(2014). Preserving compliance with security requirements in socio-technical systems . Retrieved from https://hdl.handle.net/10446/324068
File allegato/i alla scheda:
File Dimensione del file Formato  
FM +2014+Preserving_Compliance_with_Security_Requirements_in_Socio-Technical_Systems_CSPForum14.pdf

Solo gestori di archivio

Versione: postprint - versione referata/accettata senza referaggio
Licenza: Licenza default Aisberg
Dimensione del file 1.19 MB
Formato Adobe PDF
1.19 MB Adobe PDF   Visualizza/Apri
Pubblicazioni consigliate

Aisberg ©2008 Servizi bibliotecari, Università degli studi di Bergamo | Terms of use/Condizioni di utilizzo

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10446/324068
Citazioni
  • Scopus 9
  • ???jsp.display-item.citation.isi??? ND
social impact