Talk With an Expert

Using the Department of Defense Architecture Framework to Develop Security Requirements

Using the Department of Defense Architecture Framework to Develop Security Requirements (PDF, 3.30MB)Published: 10 Feb, 2014
Created by:
James E. A. Richards

Requirements for security in an organization or enterprise that uses information technology can be difficult to develop, given the complex organizational policies, technologies and processes that affect each requirement. Integrated architectures can serve as a vehicle to bring order to this complexity, and if constructed using a common data model, can be reused when developing future requirements. This paper outlines a basic approach to using an integrated architecture, built using the Department of Defense Architecture Framework (DODAF), to derive security requirements. It also examines a case study that illustrates the potential use of these techniques, and provides an overview of the relevant portions of DODAF.