Strategies for Developing Policies and Requirements for Secure Electronic Commerce Systems
نویسندگان
چکیده
While the Internet is dramatically changing the way business is conducted, security and privacy issues are of deeper concern than ever before. A primary fault in evolutionary electronic commerce systems is the failure to adequately address security and privacy issues; therefore, security and privacy policies are either developed as an afterthought to the system or not at all. One reason for this failure is the difficulty in applying traditional software requirements engineering techniques to systems in which policy is continually changing due to the need to respond to the rapid introduction of new technologies which compromise those policies. Security and privacy should be major concerns from the onset, but practitioners need new systematic mechanisms for determining and assessing security and privacy. To provide this support, we employ scenario management and goal-driven analysis strategies to facilitate the design and evolution of electronic commerce systems. Risk and impact assessment is critical for ensuring that system requirements are aligned with an enterprise’s security policy and privacy policy. Consequently, we tailor our goalbased approach by including a compliance activity to ensure that all policies are reflected in the actual system requirements. Our integrated strategy thus focuses on the initial specification of security policy and privacy policy and their operationalization into system requirements. The ultimate goal of our work is to demonstrate viable solutions for supporting the early stages of the software lifecycle, specifically addressing the need for novel approaches to ensure security and privacy requirements coverage.
منابع مشابه
Chapter 1 STRATEGIES FOR DEVELOPING POLICIES AND REQUIREMENTS FOR SECURE ELECTRONIC COMMERCE SYSTEMS
While the Internet is dramatically changing the way business is conducted, security and privacy issues are of deeper concern than ever before. A primary fault in evolutionary electronic commerce systems is the failure to adequately address security and privacy issues; therefore, security and privacy policies are either developed as an afterthought to the system or not at all. One reason for thi...
متن کاملRequirement Elicitation Based on Goals with Security and Privacy Policies in Electronic Commerce
This paper describes a method for requirements elicitation based on goals for electronic commerce systems in agreement with security and privacy polices of the site. The method integrates the UWA approach [18] with the GBRAM method [3] for developing requirements policies for secure electronic commerce systems. The resulting method has the objective to guarantee that existing security and priva...
متن کاملAnalyzing Knowledge of Rural Cooperatives Managers in Khouzestan Province toward Electronic Commerce
The purpose of this research was analyzing knowledge of rural cooperatives managers in Khouzestan province toward electronic commerce, Iran. The research method was correlative descriptive. The population of this study included rural cooperatives managers in Khuzestan province. The total number of members was 101 people. Due to the limited population, census method was used. Questionnaire relia...
متن کاملAnalyzing Attitude of Rural Cooperatives Managers in Khouzestan Province toward Electronic Commerce
The purpose of this research was analyzing attitude of rural cooperatives managers in Khouzestan province toward electronic commerce, Iran. The research method was correlative descriptive. The population of this study included rural cooperatives managers in Khuzestan province. The total number of members was 101 people. Due to the limited population, census method was used. Questionnaire reliab...
متن کاملThe Study of Differences between E-commerce Impacts on Developed Countries and Developing Countries, Case Study: USA and Iran
This study determines the impact of E-commerce (EC) on some of important economic criteria including total factor productivity( TFP) of Iran country as a developing country in comparison with US standard as a developed country through analyzing and calculating interrelated issues. The model is based on both econometrics and growth accounting approach to fill the gaps of previous studies. On the...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2000