What model describes those characteristics of security engineering processes essential to ensure good security engineering?
-
Systems Security Engineering Capability Maturity Model (SSE-CMM)
-
Capability Maturity Model Integration (CMMi)
-
Bell-LaPadula model
-
Systems Engineering Capability Maturity Model (SE-CMM)
SSE-CMM (Systems Security Engineering Capability Maturity Model) specifically describes the characteristics of security engineering processes. It provides a framework for assessing and improving the capability of security engineering processes, unlike CMMi (general software engineering) or Bell-LaPadula (access control model).
The Systems Security Engineering Capability Maturity Model (SSE-CMM) is specifically designed to describe the essential characteristics of an organization's security engineering process to ensure good security engineering practice and maturity. CMMI is a general process-improvement model not specific to security engineering. The Bell-LaPadula model is a formal access-control/confidentiality model, not a process maturity framework. SE-CMM (without the security-specific 'SSE') is the general systems engineering maturity model, not the security-focused variant being asked about.