This document presents a research effort aimed at enhancing the Descartes specification language with a secure policy framework to better integrate security requirements into the software development life cycle (SDLC). The framework introduces formal methods for specifying, validating, and analyzing security policies, which are essential for managing software security in various applications. Key components of the framework include policy entities, a policy manager, and a knowledge base, enabling the specification of secure policies through adapted concepts from existing methodologies.
Related topics: