preview

The Paradigm Of Multilateral Security

Decent Essays

Today, the established way for describing security requirements, as reflected for example in the Common Criteria, an international standard to achieve comparability of independent IT security evaluations, starts with a description of the functional requirements, the system architecture, and its working environment. It then continues with a threat analysis that describes envisaged threats, possibly followed by an evaluation of the severity of threats through a risk analysis and ends with the definition of a security policy. But nowadays, the world is not as simple as that: in civil systems, in which we are interested, there are many more stakeholders who have an interest in an asset than just the owner of the IT system. More often than not, stakeholders have conflicting interests with respect to assets. The paradigm of multilateral security acknowledges this fact. Multilateral security contradicts the traditional view, which assumes that there is a ‘‘trusted tribe’’ who has a homogeneous set of security requirements against the rest of the world. But this traditional assumption still heavily influences common approaches toward security engineering. To take multilateral security seriously in security requirements engineering (SRE), a requirements engineering process must support engineers in identifying security goals of the security stakeholders, and in resolving conflicts among them—and in the reconciliation of security goals and other, notably functional, requirements.

Get Access