The objective is to develop Security, Dependability and Privacy patterns at the level of organization, including legal and procedural aspects, starting from the definition of the conceptual framework, the specification languages and graphical formats, and the instantiation on concrete libraries focussing on the SERENITY application scenarios defined in Activity A7.
Definition of the conceptual framework
This task will involve the identification of the conceptual framework for the expression of the legal, organizational and other requirements for security and privacy. It will produce a number of versions to adapt to the requirements of the concrete SERENITY validation scenarios until the first overall version of the Security and Privacy patterns.
This task will involve the identification of the language primitives and the graphical notations for end-users to express legal, organizational and other requirements for security and privacy. Also this task will produce a number of versions to adapt to the requirements of the concrete SERENITY validation scenarios. It will produce a first preliminary version and then an update with each new release of the Security and Privacy patterns. It will synchronize with A6 for the actual syntax and management framework of patterns and with A4 for the definition of traceability relations that indicate how security and privacy requirements are realised by solutions at this layer.
This task will involve the actual design and concrete definition of security and privacy patterns at the legal, organizational and business level for the SERENITY. The release of this activity will be done by versioning and the first release will be due at M16.
- A1.D3.1 - Initial set of Security and privacy patterns at organizational level [report] [public]
- A1.D3.2 - Extended set of S&D patterns at organizational level [report] [public]
- A1.D3.3 - Final set of S&D patterns at organizational level [report] [public] (due 2009).