Good Security Practices for Electronic Commerce, Including Electronic Data Interchange

Abstract

Electronic commerce (EC) is the use of documents in electronic form, rather than paper, for carrying out functions of business or government that require interchange of information, obligations, or monetary value between organizations. Electronic data interchange (EDI) is the computer-to-computer transmission of strictly formatted messages that represent documents; EDI is an essential component of EC. With EC, human participation in routine transaction and decisions are made more rapidly, leaving much less time to detect and correct errors. This report presents security procedures and techniques (which encompass internal controls and checks) that constitute good practices in the design, development, testing and operation of EC systems. Principles of risk management and definition of parameters for quantitative risk assessments are provided. The content of the trading partner agreement is discussed and the components of EC including the network(s) connecting the partners, are described. Some security techniques considered include audit trails, contingency planning, use of acknowledgments, electronic document management, activities of supporting networks, user access controls to systems and networks, and cryptographic techniques for authentication and confidentiality.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Dec 01, 1993
Accession Number
ADA405104

Entities

People

  • Roy G. Saltman

Organizations

  • National Institute of Standards and Technology

Tags

Communities of Interest

  • Cyber
  • Energy and Power Technologies
  • Engineered Resilient Systems
  • Human Systems

DTIC Thesaurus Topics

  • Application Software
  • Authentication
  • Commerce
  • Communications Protocols
  • Computer Access Control
  • Computers
  • Control Systems
  • Cybersecurity
  • Data Processing
  • Databases
  • Department Of Veterans Affairs
  • Electronic Commerce
  • Information Systems
  • Management Personnel
  • Risk
  • Risk Analysis
  • Security

Fields of Study

  • Computer science

Readers

  • Cybersecurity.
  • Small Business Innovation Research Program (SBIR) EDI Research and Innovation.
  • Systems Analysis and Design

Technology Areas

  • Microelectronics