A Systematic Method for Constructing ICT Supply Chain Security Requirements


연구 분야: Verification



학회: International Symposium on Emerging Information Security and Applications


초록

This paper studies how to construct Information and Communication Technology (ICT) supply chain security requirements from the perspective of ICT supply chain security assurance. Firstly, the security environment of ICT supply chain is established through ICT supply chain relationship, product life cycle stages, security driving factors and security properties. Then it is proposed to derive ICT supply chain security requirements from regulatory requirements and security best practices, each requirement is validated through the Asset-Threat-Objective-Requirement (ATOR) methodology, and 10 categories of 100 items of ICT supply chain security requirements are established in this way. Finally, the application scenarios and usages of ICT supply chain security requirements are described.


Author Profile
Yinxing Wei

ZTE Corporation Nanjing China

China
Author Profile
Jun Zheng

ZTE Corporation Nanjing China

China
Author Profile
Hong Zhong

ZTE Corporation Nanjing China

China

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 China
사이트 Springer
좋아요 수 0

연관 논문 목록 (52건)