Server module updated
Just uploaded the updated Server module to align with the role changes we made to the client. I found a few additional errors as I went through that I corrected, and hopefully these should now be quite stable.
Updates, insights, and commentary from the OSA community. Tracking the evolution of security architecture since 2008.
Just uploaded the updated Server module to align with the role changes we made to the client. I found a few additional errors as I went through that I corrected, and hopefully these should now be quite stable.
During my discussion with Claudiu (whom I appreciate as great expert in the area of secure development), we came up with some further thoughts on what drives security requirements. Also we agreed that the currently posted categorization in the Security Requirements article (under Foundations->Definitions) is not orthogonal. Meaning that a requirement can ambigously belong to two categories. However we believe that it is never the less valuable to understand what are the potential sources for requirements.
Finally got the Client module uploaded tonight after messing around all evening with it. There are so many controls that it takes ages to be sure that you have them correctly assigned to the roles, labelled and hyperlinked. If you are using IE I really encourage you to try with Firefox, Safari or Opera which support SVG graphics. That way you get the links to controls on the diagram itself, along with tooltips.
I'm working at the moment on the Client and Server modules. These form the foundations of the OSA pattern library as they will be used and referenced many times. It's taking time to get these modules rights which is slowing progress.