To main content

Specifying Legal Risk Scenarios Using the CORAS Threat Modelling Language

Abstract

The paper makes two main contributions: (1) It presents experiences from using the CORAS language for security threat modelling to specify legal risk scenarios. These experiences are summarised in the form of requirements to a more expressive language providing specific support for the legal domain. (2) Its second main contribution is to present ideas towards the fulfilment of these requirements. More specifically, it extends the CORAS conceptual model for security risk analysis with legal concepts and associations. Moreover, based on this extended conceptual model, it introduces a number of promising language constructs addressing some of the identified deficiencies.

Category

Academic chapter/article/Conference paper

Language

English

Author(s)

  • Mass Soldal Lund

Affiliation

  • SINTEF Digital / Sustainable Communication Technologies

Year

2005

Publisher

Springer

Book

Trust Management, Third International Conference, iTrust 2005, Proceedings

Issue

3477

ISBN

9783540260424

Page(s)

45 - 60

View this publication at Cristin