<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Feb</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Patterns- and Security-Requirements-Engineering-based Support for Development and Documentation of Security Standard Compliant ICT Systems ?</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Kristian Beckers</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maritta Heisel (PhD Supervisor)</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>paluno - The Ruhr Institute for Software Technology University of Duisburg-Essen</institution>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2012</year>
      </pub-date>
      <volume>15</volume>
      <issue>2012</issue>
      <abstract>
        <p>Aligning an ICT system with a security standard is a challenging task, because of the sparse support for development and documentation that these standards provide. We create patterns for the elements of trustworthiness: security, risk management, privacy, and law. The instantiations of these patterns are used to support the development and documentation of ICT systems according to security standards. In addition, we de ne relations between security standards and security requirements engineering approaches.</p>
      </abstract>
      <kwd-group>
        <kwd>security standards</kwd>
        <kwd>requirements engineering</kwd>
        <kwd>security</kwd>
        <kwd>patterns</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Security is a system property of ICT systems [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ] and an acceptable security
level has to be achieved for the entire system. Security standards exist that
provide relevant methods for achieving this goal. However, aligning ICT systems
with security standards is di cult, because the standards provide only sparse
support for system development and documentation. For example, assembling
an information security management system (ISMS) according to the ISO 27001
requires a scope and boundaries description among its initial steps. The required
input is to consider \characteristics of the business, the organization, its location,
assets and technology"[3, p. 4].
      </p>
      <p>Security requirements engineering (SRE) methods, on the other hand,
provide structured elicitation and analysis of security requirements. This structured
elicitation and analysis of security requirements of SRE methods is useful for
numerous security engineering contexts. Therefore, we propose to use SRE methods
to support security engineers in the development and documentation of
trustworthy ICT systems that are compliant to security standards.</p>
      <p>
        This thesis is inspired by the work of Gamma et. al [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], which manages
comprehensible to describe design problems and solutions in a fairly easy way. We
aim to accomplish the same for design and documentation problems of
trustworthy ICT systems. Security engineering \requires cross-disciplinary expertise" [5,
p. 3]. Patterns provide the means to collect this expertise and instantiate it to a
given security engineering problem. We de ne trustworthiness as a combination
of security, risk management, privacy and compliance attributes. All of these
attributes are also required by security standards, e.g., ISO 27001. Hence, we
restrict patterns in this work to security, law, privacy, and risk management
patterns.
      </p>
      <p>The outcome of this analysis answers the research question, if and to what
extent patterns and SRE approaches can support the development of a
security standard compliant ICT system. Moreover, it answers the question in what
way patterns and SRE methods provide the required documentation for a
security standard compliant ICT system and how existing pattern-based and SRE
documentation can be re-used for an aforementioned system.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Previous Work</title>
      <p>
        ICT systems keep increasing their functionality and distribution in recent years.
Unfortunately this increase in complexity of ICT systems leads also to an increase
in security problems for instance in cloud computing systems (or short clouds)
[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>
        We developed a pattern-based approach to support the context
establishment and asset identi cation in the scope of cloud computing systems for the
ISO 27005 [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] standard [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. Our work shows a cloud system analysis pattern and
di erent kinds of stakeholder templates serve to understand and describe a given
cloud development problem. We illustrated our support using an online banking
cloud scenario, presented in in Fig. 1. Our cloud system analysis pattern in Fig. 1
that provides a conceptual view on cloud computing systems and serves to
systematically analyse stakeholders and requirements. The notation used to specify
the pattern is based on UML1 notation, i.e. the stick gures represent roles,
the boxes represent concepts orientates of the real world, the named lines
represent relations (associations) equipped with cardinalities, the un lled diamond
represents a \part-of" relation, and the un lled triangles represent inheritance.
      </p>
      <p>A Cloud is embedded into an environment consisting of two parts, namely
the Direct System Environment and the Indirect System Environment. The
Direct System Environment contains stakeholders and other systems that directly
interact with the Cloud, i.e. they are connected by associations. Moreover,
associations between stakeholders in the Direct and Indirect System Environment
exist, but not between stakeholders in the Indirect System Environment and
the cloud. Typically, the Indirect System Environment is a signi cant source for
compliance and privacy requirements.</p>
      <p>The Cloud Provider owns a Pool consisting of Resources, which are divided
into Hardware and Software resources. The provider o ers its resources as
Services, i.e. IaaS, PaaS, or SaaS. The boxes Pool and Service in Fig. 1 are hatched,
1 Uni ed Modeling Language: http://www.omg.org/spec/UML/2.3/
Hulda
1..*</p>
      <p>Owns 1..*</p>
      <p>IsBasedOn
1..*
Pool
1..* Data Center</p>
      <p>Server
Network and
Virtualization
Software</p>
      <p>Internal Development Unit
InputBy/OutputTo</p>
      <p>1..*
Legislator US</p>
      <p>Domain Finance
Legislator Germany Legislator EU</p>
      <p>Has</p>
      <p>IsMonitoredBy
UMseVadicrBthuyianle1..*Is1C..*omplementedBy* SAWeperpvbleiscrea,rtevioetcnr., * BuiltAndCustomizedBy</p>
      <p>*
UPseroIdngBCtreyalromfuamdc*1.ei.n*g I1s.C.*omplementedBy* SBOoafnntwklinianerge * BuiltBy *
BSOaennrvlkiinicneeg 1Is..*ComplementedBy * TraDna*staaction * *
1..*
1..*
Bank Institute
1..* 1..*
WorkFor</p>
      <p>Has
*
Bank Customer</p>
      <p>Indirect System Environment
Direct System Environment
1..*
because it is not necessary to instantiate them. Instead, the specialised cloud
services such as IaaS, PaaS, and SaaS and specialised Resources are instantiated.
The Cloud Developer represents a software developer assigned by the Cloud
Customer. The developer prepares and maintains an IaaS or PaaS o er. The IaaS
o er is a virtualised hardware, in some cases equipped with a basic operating
system. The Cloud Developer deploys a set of software named Cloud Software
Stack (e.g. web servers, applications, databases) into the IaaS in order to o er
the functionality required to build a PaaS. In our pattern PaaS consists of an
IaaS, a Cloud Software Stack and a cloud programming interface (CPI), which
we subsume as Software Product. The Cloud Customer hires a Cloud Developer
to prepare and create SaaS o ers based on the CPI, nally used by the End
Customers. SaaS processes and stores Data in- and output from the End Customers.
The Cloud Provider, Cloud Customer, Cloud Developer, and End Customer are
part of the Direct System Environment. Hence, we categorise them as direct
stakeholders. The Legislator and the Domain (and possibly other stakeholders)
are part of the Indirect System Environment. Therefore, we categorize them as
indirect stakeholders.</p>
      <p>The cloud system analysis pattern instance in Fig. 1 helps, e.g., identifying
assets by considering the instantiated boxes and the associations between the
direct stakeholders and the cloud. The associations indicate the ow of
information into and out of the cloud and therefore helps to analyze the information
assets processed and stored in the cloud. Furthermore, the associations help to
nd out about the asset owner, as the standard requires.</p>
      <p>
        Identifying relevant compliance regulations for a software system and aligning
it to be compliant is a challenging task. Hence, we already developed a
patternbased method for Identifying and analyzing laws [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. The method makes use of
di erent kinds of patterns, which help to systematically elicit relevant laws.
      </p>
      <p>
        We also analyzed the ISO 27001 standard to determine what techniques
and documentation are necessary and instrumental to develop and document
systems according to this standard [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. Based on these insights, we inspected a
number of current SRE approaches to evaluate whether and to what extent these
approaches support ISO 27001 system development and documentation. We
reuse a conceptual framework (CF) [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] originally developed for comparing SRE
methods to relate important terms, techniques, and documentation artifacts of
the security requirements engineering methods to the ISO 27001.
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>Future Work</title>
      <p>
        In the future we will extend this approach to support the documentation and
development of trustworthy ICT systems, as depicted in Fig. 2. In our approach,
we will re-use existing meta models for security standards, e.g., Sunyaev [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] and
for risk management standards, e.g., Fenz [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] and combine them into a pattern
for security and risk management standards (1). As a next step we will develop
relations from these patterns to the CF (2), which allows us to re-use the existing
relations to SRE methods (3). We combine the relations 1, 2, and 3 and, thus,
we can create transitive relations the SRE methods to multiple security and risk
management standards, e.g. ISO 27001 and Common Criteria (4).
      </p>
      <p>However, the privacy and compliance demands of trustworthy ICT systems
and security standards, e.g., ISO 27001 and Common Criteria, alike are not yet
addressed. Hence, we propose to develop relations between speci c patterns for
laws (5), risk and security (6), and privacy (7). We will also extend the CF to
enable relations to privacy and law extensions of SRE methods. The risk and
security patterns shall address issues that are not already covered by an existing
SRE method in 3. We will also develop the patterns in 5, 6, and 7, if there are
no suitable patterns available yet. As a last step we combine the relations 5, 6,
and 7 and, thus, also relate the patterns to multiple security standards, e.g. ISO
27001 and Common Criteria (8).</p>
      <p>We choose cloud computing as an example of our work. Hence, we will create
more detailed patterns for cloud systems based upon the aforementioned Cloud
System Analysis Pattern.</p>
      <p>
        Moreover, aligning clouds to meet compliance regulations is a challenging
task, because of a high number of di erent kinds of stakeholders. We will address
this problem by creating speci c cloud law analysis patterns as an extension to
our existing law pattern approach [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. Our extension will also make use of results
generated by the application of the cloud system analysis pattern.
      </p>
      <p>Security and Risk
Management</p>
      <p>Standard 1
Security and Risk
Management</p>
      <p>Standard ...</p>
      <p>Security and Risk
Management
Standard n</p>
      <p>Law Patterns
8</p>
      <p>
        We will start working on privacy patterns based upon Nissenbaum's model of
informational privacy in terms of contextual privacy [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. The model considers
the context of a given situation, the kind of information and the relation of the
information to the context. We will also compare security and risk management
patterns using existing surveys, e.g., Heyman et al. [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
      <p>The outcome of our work is a methodology for developing and documenting
ICT systems with the goal to be compliant to security standards. We aim at
developing a system of patterns supported by security requirements engineering
approaches, which can be used to improve the security of an ICT system, as well
as to generate a documentation of an ICT system. This documentation can be
used as a basis for certi cation according to a standard.</p>
      <p>
        The patterns in our work will be based upon UML and the problem frame
approach by Michael Jackson [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. In addition, essential parts of the patterns are
speci ed with a formal notation based upon the Z notation [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]. The patterns
will be derived from relevant scienti c literature, existing pattern libraries, as
well as being found in existing implementations of security standards.
      </p>
      <p>We plan to validate our work via using the methodology and the pattern
system for an ICT system and a speci c security standard. We will compare
the resulting documentation against a standard-compliant documentation that
is not based on our patterns.</p>
      <p>We conclude with a brief summary of the main bene ts of our approach:
{ A methodology for systematic pattern-based development and
documentation of ICT systems
{ Complementing patterns with existing SRE approaches in order to
completely support the implementation of sections of security standards
{ Speci c-patterns for laws, privacy, security and risk management to cover
all quality requirements of security standards
{ Ease the burden of implementing security standards</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1. P eeger, C.P., P eeger, S.L.:
          <article-title>Security In Computing. 4th edn. Prentice Hall PTR (</article-title>
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Anderson</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          : Security EngineerIng. 2nd edn. Wiley (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3. ISO/IEC: Information technology -
          <source>Security techniques - Information security management systems - Requirements</source>
          . ISO/IEC 27001,
          <article-title>International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) (</article-title>
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Gamma</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Helm</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , Johnson, R.,
          <string-name>
            <surname>Vlissides</surname>
            ,
            <given-names>J.M.</given-names>
          </string-name>
          :
          <article-title>Design Patterns: Elements of Reusable Object-Oriented Software. 1 edn</article-title>
          . Addison-Wesley
          <string-name>
            <surname>Professional</surname>
          </string-name>
          (
          <year>1994</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Bishop</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Computer Security : art and science</article-title>
          .
          <source>1st edn. Pearson</source>
          (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Beckers</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , Jurjens, J.:
          <article-title>Security and compliance in clouds</article-title>
          .
          <source>In: Information Security Solutions Europe (ISSE</source>
          <year>2010</year>
          ).
          <article-title>Securing electronic business processes : Highlights of the Information Security Solutions Europe</article-title>
          , Vieweg + Teubner (
          <year>2010</year>
          )
          <volume>91</volume>
          {
          <fpage>100</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7. ISO/IEC: Information technology
          <article-title>- security techniques - information security risk management</article-title>
          . ISO/IEC 27005,
          <article-title>International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) (</article-title>
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Beckers</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , Kuster,
          <string-name>
            <given-names>J.C.</given-names>
            ,
            <surname>Fa bender</surname>
          </string-name>
          , S.,
          <string-name>
            <surname>Schmidt</surname>
          </string-name>
          , H.:
          <article-title>Pattern-based support for context establishment and asset identi cation of the ISO 27000 in the eld of cloud computing</article-title>
          .
          <source>In: Proceedings of the International Conference on Availability, Reliability and Security (ARES)</source>
          ,
          <source>IEEE Computer Society</source>
          (
          <year>2011</year>
          )
          <volume>327</volume>
          {
          <fpage>333</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Beckers</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , Kuster,
          <string-name>
            <given-names>J.C.</given-names>
            ,
            <surname>Fa bender</surname>
          </string-name>
          , S.,
          <string-name>
            <surname>Schmidt</surname>
          </string-name>
          , H.:
          <article-title>A pattern-based method for identifying and analysing laws</article-title>
          .
          <source>In: REFSQ</source>
          . (
          <year>2012</year>
          ) to be published.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Beckers</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fa bender</surname>
          </string-name>
          , S.,
          <string-name>
            <surname>Heisel</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          , Kuster,
          <string-name>
            <given-names>J.C.</given-names>
            ,
            <surname>Schmidt</surname>
          </string-name>
          , H.:
          <article-title>Supporting the development and documentation of ISO 27001 information security management systems through security requirements engineering approaches</article-title>
          .
          <source>In: Proceedings of the International Symposium on Engineering Secure Software and Systems (ESSoS)</source>
          .
          <source>LNCS</source>
          , Springer (
          <year>2012</year>
          ) to be published.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Fabian</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          , Gurses,
          <string-name>
            <given-names>S.</given-names>
            ,
            <surname>Heisel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Santen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            ,
            <surname>Schmidt</surname>
          </string-name>
          , H.:
          <article-title>A comparison of security requirements engineering methods</article-title>
          . Requirements Engineering { Special Issue on Security
          <source>Requirements Engineering</source>
          <volume>15</volume>
          (
          <issue>1</issue>
          ) (
          <year>2010</year>
          )
          <volume>7</volume>
          {
          <fpage>40</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Sunyaev</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Health-Care Telematics in Germany: Design and Application of a Security Analysis Method. 1st edn</article-title>
          . Gabler Verlag (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Fenz</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ekelhart</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Neubauer</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Information security risk management: In which security solutions is it worth investing?</article-title>
          <source>Communications of the Association for Information Systems</source>
          <volume>28</volume>
          (
          <issue>1</issue>
          ) (5
          <year>2011</year>
          )
          <volume>329</volume>
          {
          <fpage>356</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Nissenbaum</surname>
          </string-name>
          , H.:
          <article-title>Privacy in Context: Technology, Policy, and the Integrity of Social Life. 1st edn</article-title>
          .
          <source>Stanford</source>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Heyman</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Scandariato</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Huygens</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joosen</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          :
          <article-title>Using security patterns to combine security metrics</article-title>
          .
          <source>In: Proceedings of the International Conference on Availability, Reliability and Security (AReS)</source>
          ,
          <source>IEEE Computer Society</source>
          (
          <year>2008</year>
          )
          <volume>1156</volume>
          {
          <fpage>1163</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Jackson</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <string-name>
            <given-names>Problem</given-names>
            <surname>Frames</surname>
          </string-name>
          .
          <article-title>Analyzing and structuring software development problems</article-title>
          . Addison-Wesley (
          <year>2001</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17. ISO/IEC: Information technology {
          <article-title>Z formal speci cation notation { Syntax, type system and semantics</article-title>
          . ISO/IEC 13568,
          <article-title>International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) (</article-title>
          <year>2002</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>