System-Agnostic Security Domains for Understanding and Prioritizing Systems Security Engineering Efforts
Document Type
Article
Publication Date
2017
Abstract
As modern systems continue to increase in size and complexity, current systems security practices lack an effective approach to prioritize and tailor systems security efforts to successfully develop and field systems in challenging operational environments. This paper uniquely proposes seven system-agnostic security domains, which assist in understanding and prioritizing systems security engineering (SSE) efforts. To familiarize the reader with the state-of-the-art in SSE practices, we first provide a comprehensive discussion of foundational SSE concepts, methodologies, and frameworks. Next, the seven system-agnostic security domains are presented for consideration by researchers and practitioners. The domains are intended to be representative of a holistic SSE approach, which is universally applicable to multiple systems classes and not just a single-system implementation. Finally, three examples are explored to illustrate the utility of the system-agnostic domains for understanding and prioritizing SSE efforts in information technology systems, Department of Defense weapon systems, and cyber-physical systems.
DOI
10.1109/ACCESS.2017.2670781
Source Publication
IEEE Access
Recommended Citation
S. Khou, L. O. Mailloux and J. M. Pecarina, "System-Agnostic Security Domains for Understanding and Prioritizing Systems Security Engineering Efforts," in IEEE Access, vol. 5, pp. 3465-3474, 2017. https://doi.org/10.1109/ACCESS.2017.2670781
Comments
The "Link to Full Text" button on this page loads the open access article, hosted at IEEE. The publisher retains permissions to re-use and distribute this article.
The linked article is subject to the following terms by the publisher: © 2017 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.