Activities which increase trust to information systems are the condition for realisation of information security aims. The article describes requirements specification of IS according to the PN-ISO/IEC 17799:2003 norm and engineering principles for information technology security according to NIST. The analysis of the correspondence between norms and principles is discussed in the paper.
Referring to the growing significance of infomation security, the issues of requirements specification as a basic aspect of implementation of certain protection solutions are presented. The authoress describes a standard process of requirements engineering. The place of requirements specification in the information security life cycle is indicated. Risk estimation as a method supporting decisions concerning introduction of particular securities is discussed.
JavaScript jest wyłączony w Twojej przeglądarce internetowej. Włącz go, a następnie odśwież stronę, aby móc w pełni z niej korzystać.