The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

Good Security Practices for Electronic COmmerce, Including Electronic Data Interchange

Author

Roy G. Saltman, ed.

Entry type

techreport

Abstract

Electronic Commerce (EC) is the use of documents in electronic form, rather than paper, for carrying out functions of business or government that require interchange of information, obligations, or monetary value between organizations. ELectronic data interchange (EDI) is the computer -to-computer transmission of strictly formatted messages that represent documents; EDI is an essential component of EC. With EC, human participation in routine transaction and decisions are made more rapidly, leaving much less time to detect and correct errors. This report presents security procedures that and techniques (which encompass internal controls and checks) and operation of EC systems. Principles of risk management and definition of parameters for quantitative risk assessments are provided. The content of the trading partner agreement is discussed, and the components of EC, including the network (s) connecting the partners, are described. Some security techniques considered include audit trails, contingency planning, use of acknowledgements, electronic document management, activities of supporting networks, user access controls to systems and networks, and cryptographic techniques for authentication and confidentiality.

Date

1993 – December

Institution

NIST

Key alpha

Saltman

Pages

66

Publisher

National Institute of Standards and Technology Special Publci

Publication Date

0000-00-00

Coden

NSPUE2

Contents

1 Management of Security for Electronic Commerce 2 Identification of Electronic Commerce System Risks 3 Good Security Practices

Language

English

Location

A hard-copy of this is in Haas

Subject

Electronic Commerce

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.