On the Operational Security Assurance Evaluation of Networked IT Systems

  • Authors:
  • Artur Hecker;Michel Riguidel

  • Affiliations:
  • Institut Télécom, Télécom ParisTech, LTCI CNRS,;Institut Télécom, Télécom ParisTech, LTCI CNRS,

  • Venue:
  • NEW2AN '09 and ruSMART '09 Proceedings of the 9th International Conference on Smart Spaces and Next Generation Wired/Wireless Networking and Second Conference on Smart Spaces
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we introduce and discuss the system security assurance assessment problematic. We first define and position security assurance in the context of modern networked IT systems. We then motivate and discuss its use. Next, we define the problem of the operational security assurance evaluation. We present and compare two orthogonal approaches to such an evaluation: a spec-based approach, which is an extension of the Common Criteria to systems in operation, and a direct approach, which relies on network management. Finally, we show examples and the pros and the cons of both approaches.