-
Key: UAF14-208
-
Status: open
-
Source: RTX ( Mr. Sam Biller)
-
Summary:
The EA Guide and the formal UAF documents suggest that UAF can be used to capture non-security risks at various levels of abstraction of the AD. The view specifications and UAFML limit the mitigation of a risk to a security control. It appears that an operational or resource mitigation should be elements that are able to mitigate a risk. The current metamodel only allows risks to affect those elements. Some rework in this area would improve the ability to capture non-security risks for ADs. Please see attached pdf for additional information.
-
Reported: UAF 1.2 — Wed, 8 Nov 2023 21:44 GMT
-
Updated: Fri, 20 Dec 2024 14:57 GMT
-
Attachments:
- UAF Non-Security Risk 11-8-2023.pdf 855 kB (application/pdf)
UAF14 — Non-Security Risks
- Key: UAF14-208
- OMG Task Force: Unified Architecture Framework (UAF) 1.4 RTF