본문 바로가기
  • Home

Research on Quantitative Security Requirements Modeling and STRM-based Architecture Mapping in ITU-T X.805 & X.1601

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2026, 31(7), pp.107~116
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science
  • Received : April 13, 2026
  • Accepted : June 17, 2026
  • Published : July 31, 2026

Gyeongsu Kim 1 Hyunsu Yoo 1 Hanjin Lee ORD ID 2

1고려대학교
2한동대학교

Accredited

ABSTRACT

As financial institutions increasingly adopt hybrid and multi-cloud environments, the complexity of security architecture design has risen due to unclear boundaries and multi-layered data flows. Existing approaches rely heavily on expert experience and manual processes, causing inconsistencies and limited reproducibility. This study proposes a structured and quantitative methodology for deriving security requirements and mapping them to architecture design based on a unified Security Technology Reference Model (STRM) integrating standards such as ITU-T X.805 and X.1601. The model introduces a formalized Security Requirement Code (SEC) data model, a matrix-based mapping structure (Protection Object x Security Function), and a quantitative coverage metric for evaluating completeness. This proposed model improves coverage, reduces omission, and enhances design consistency.

Citation status

* References for papers published after 2025 are currently being built.