Authors
Naved Ahmed, Raimundas Matulevičius
Publication date
2014/6/1
Journal
Computer Standards & Interfaces
Volume
36
Issue
4
Pages
723-733
Publisher
North-Holland
Description
Business process modelling and security engineering are two important concerns when developing information system. However current practices report that security is addressed at the later development stages (i.e. design and implementation). This raises a question whether the business processes are performed securely. In this paper, we propose a method to introduce security requirements to the business processes through the collaboration between business and security analysts. To support this collaboration we present a set of security risk-oriented patterns. We test our proposal in two industrial business models. The case findings characterise pattern performance when identifying business assets, risks, and countermeasures.
Total citations
2013201420152016201720182019202020212022202320244214985765972
Scholar articles