This paper proposes a formal definition of "security" in a composite system. By composite system, we mean a system which is composed of an automated and a human part. This split of systems in two parts characterizes the computer environment where human presence is unavoidable. Our results are a generalization of [6]. The scope of [6] was limited to three access modes, that is read, write, execute. In this paper, we extend this scope by addressing all possible operations. We also provide a syntactic way, based on the proposed security formal definition, of describing threats during the requirement analysis process. To handle the security problem when designing a system, it is important to integrate threats in the requirements document. Up to now, there were only "methods" to derive threats [arbitrary or threat trees method], not to express them unambiguously.
Kabasele-Tenday, J. (1998). Specifying security in a composite system. Lecture Notes in Computer Science, 1396, 246-255. https://doi.org/10.1007/BFb0030425 (Original work published 1998)