Archive - Central European Conference on Information and Intelligent Systems, CECIIS - 2008

Font Size: 
Systems Security Engineering Capability Maturity Model with support of simulation and knowledge management
Danijela Bambir, A1eljko Hutinski, Vesna DuA!ak

Last modified: 2008-08-25

Abstract


With the increasing reliance of society on information, the protection of that information and related system is becoming extremely relevant. For that reason, security engineering expanded its domain to many areas like financial transactions, contractual agreements, personal information and the Internet. Logically, then appeared a need for appropriate methods and practices required by various participants in security engineering process. As a result, SSE-CMM was developed, describing the essential characteristics of an organization's security engineering process. The model consists of five capability levels that address different maturity stages. In this paper it is shown that simulation and knowledge management can be used to support improvement at all five levels of the SSE-CMM. Simulation and KM capabilities at each SSE-CMM level build upon the capabilities of the preceding levels, and match the needs of the security engineering practices at that capability level.

Full Text: PDF