Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

SYSTEMS SECURITY ENGINEERING: WHOSE JOB IS IT ANYWAY?

View through CrossRef
ABSTRACTThis article delivers a look at current and evolving policy, guidance, and standards surrounding security activities in the systems engineering lifecycle. Emphasis is placed on systems security engineering (SSE) and how application of systems engineering concepts and processes in an agile manner (agile systems engineering) throughout the lifecycle is the way to deal with the dynamic and diverse world of cyber threats to a system (Dove 2014). This paper is a follow‐on to “Response to Cyber Security Demands for Agility” (Nejib‐Beyer 2014) published in the International Council on Systems Engineering (INCOSE) INSIGHT in 2014. The focus of that research was bringing attention to cyber security and the importance of other disciplines towards contributing to secure systems. Since that time many of these domains have further developed their own standards, processes, and guidance in the area of cyber security. What we require now is a way to take these domain‐focused concepts and integrate them into and across a systems lifecycle. The best way to achieve this is as part of the systems engineering function. Designing and building secure systems requires a seamless integration of security into systems engineering processes and agile methodologies adopted to constantly revisit, reevaluate, and re‐design as part of a risk management process. The framework that will be discussed in this paper will focus on taking currently evolving guidance in SSE and breaking that down into products and tools for systems engineers to easily determine the relationship and value between SSE and systems engineering. In addition, quick reference guides will further enhance and enable successful development and integration of SSE artifacts into systems engineering artifacts. One of the companion pieces needed in the existing SSE documentation is a mapping of work products/artifacts generated during the lifecycle/technical processes and the responsible and contributing parties. Critical to the success of the new guidance, such as the National Institute of Standards and Technology (NIST) Special Publication (SP) 800‐160, Systems Security Engineering, is a clear accountability and acceptance of all disciplines on their contributions and influence towards developing a secure system. We present an SSE roles and responsibilities framework concept for consideration. The framework is an implementation tool to be used along with existing guidance in the area of SSE and systems engineering to clearly demonstrate that program protection is not the responsibility of any one person or discipline, it is the responsibility of an entire team of individuals planning, developing, deploying, operating & maintaining (O&M), and retiring a system. SSE is the “glue” that binds all of this together during the systems engineering lifecycle to enhance system security.
Title: SYSTEMS SECURITY ENGINEERING: WHOSE JOB IS IT ANYWAY?
Description:
ABSTRACTThis article delivers a look at current and evolving policy, guidance, and standards surrounding security activities in the systems engineering lifecycle.
Emphasis is placed on systems security engineering (SSE) and how application of systems engineering concepts and processes in an agile manner (agile systems engineering) throughout the lifecycle is the way to deal with the dynamic and diverse world of cyber threats to a system (Dove 2014).
This paper is a follow‐on to “Response to Cyber Security Demands for Agility” (Nejib‐Beyer 2014) published in the International Council on Systems Engineering (INCOSE) INSIGHT in 2014.
The focus of that research was bringing attention to cyber security and the importance of other disciplines towards contributing to secure systems.
Since that time many of these domains have further developed their own standards, processes, and guidance in the area of cyber security.
What we require now is a way to take these domain‐focused concepts and integrate them into and across a systems lifecycle.
The best way to achieve this is as part of the systems engineering function.
Designing and building secure systems requires a seamless integration of security into systems engineering processes and agile methodologies adopted to constantly revisit, reevaluate, and re‐design as part of a risk management process.
The framework that will be discussed in this paper will focus on taking currently evolving guidance in SSE and breaking that down into products and tools for systems engineers to easily determine the relationship and value between SSE and systems engineering.
In addition, quick reference guides will further enhance and enable successful development and integration of SSE artifacts into systems engineering artifacts.
One of the companion pieces needed in the existing SSE documentation is a mapping of work products/artifacts generated during the lifecycle/technical processes and the responsible and contributing parties.
Critical to the success of the new guidance, such as the National Institute of Standards and Technology (NIST) Special Publication (SP) 800‐160, Systems Security Engineering, is a clear accountability and acceptance of all disciplines on their contributions and influence towards developing a secure system.
We present an SSE roles and responsibilities framework concept for consideration.
The framework is an implementation tool to be used along with existing guidance in the area of SSE and systems engineering to clearly demonstrate that program protection is not the responsibility of any one person or discipline, it is the responsibility of an entire team of individuals planning, developing, deploying, operating & maintaining (O&M), and retiring a system.
SSE is the “glue” that binds all of this together during the systems engineering lifecycle to enhance system security.

Related Results

Work Values
Work Values
Research has identified TV series and, also more recently social media, as different actors in vocational socialization, providing individuals with career-related information (Levi...
Information Security in Artificial Intelligence: A Study of the possible intersection
Information Security in Artificial Intelligence: A Study of the possible intersection
1. IntroductionArtificial Intelligence or A.I attempts to understand intelligent entities, and strives to build ones. And it is obvious that computers with human-level intelligence...
Early Childhood Teacher Job Satisfaction in Terms of Technostress and Work-Family Conflict in Indonesia
Early Childhood Teacher Job Satisfaction in Terms of Technostress and Work-Family Conflict in Indonesia
Teachers have an important and primary role in the education system. The achievement of the teacher's role in education will have an impact on job satisfaction. This study aims to ...
JOB DEMANDS DAN JOB RESOURCES (JD-R) PENGARUHNYA TERHADAP PRODUKTIVITAS KARYAWAN
JOB DEMANDS DAN JOB RESOURCES (JD-R) PENGARUHNYA TERHADAP PRODUKTIVITAS KARYAWAN
            Produktivitas karyawan yang stabil dan sesuai target adalah merupakan faktor yang sangat penting untuk menjaga  kelangsungan hidup perusahaan tetapi  untuk menciptakan ...
A causal model of job stress among Thai nurse-midwives
A causal model of job stress among Thai nurse-midwives
Abstract Objective To test a causal model of job stress among nurse-midwives working in labor and delivery units in Thail...
Job Standardization and Employee Voice
Job Standardization and Employee Voice
An organization expects its employees to comply with job standardization to improve its production efficiency, while also expecting them to make suggestions to improve their job pe...
Anteseden Kinerja Karyawan PT. Bank Mandiri Persero Tbk Area Jakarta Cikini
Anteseden Kinerja Karyawan PT. Bank Mandiri Persero Tbk Area Jakarta Cikini
AbstractThe problem of this research comes from a phenomenon that occurred to employees in PT. Bank Mandiri (Persero) Tbk Area Jakarta Cikini. The objectives of the research are to...

Back to Top