Investigating fulfilment of traceability requirements in a combined process for safety and security assessments
by Vikash Katta; Christian Raspotnig; Peter Karpati; Tor Stålhane
International Journal of Critical Computer-Based Systems (IJCCBS), Vol. 6, No. 2, 2015

Abstract: Combined harm assessment of safety and security for information systems (CHASSIS) method defines a unified process for safety and security assessments. CHASSIS applies techniques from safety and security fields - e.g., misuse case and HAZOP - to identify and model hazards, threats, safety and security requirements to a system. Ensuring traceability between safety and security requirements as well as other artefacts is one of the important tasks required to provide safety and security assurance. In this paper, we present an approach for traceability, called SaTrAP, which was used to provide traceability support to CHASSIS. We discuss the application of SaTrAp and CHASSIS with the help of an ATM remote tower example. We evaluate whether CHASSIS together with SaTrAp fulfils the traceability requirements set by standards. In this regard, we have analysed regulations/standards from ATM domain for requirements on traceability. We also analysed how security has been addressed by these standards.

Online publication date: Fri, 11-Dec-2015

The full text of this article is only available to individual subscribers or to users at subscribing institutions.

 
Existing subscribers:
Go to Inderscience Online Journals to access the Full Text of this article.

Pay per view:
If you are not a subscriber and you just want to read the full contents of this article, buy online access here.

Complimentary Subscribers, Editors or Members of the Editorial Board of the International Journal of Critical Computer-Based Systems (IJCCBS):
Login with your Inderscience username and password:

    Username:        Password:         

Forgotten your password?


Want to subscribe?
A subscription gives you complete access to all articles in the current issue, as well as to all articles in the previous three years (where applicable). See our Orders page to subscribe.

If you still need assistance, please email subs@inderscience.com