Information systems security criticality and assurance evaluation

  • Authors:
  • Moussa Ouedraogo;Haralambos Mouratidis;Eric Dubois;Djamel Khadraoui

  • Affiliations:
  • Public Research Center Henri Tudor, Luxembourg and School of Computing, IT and Engineering, University of East London, England;School of Computing, IT and Engineering, University of East London, England;Public Research Center Henri Tudor, Luxembourg;Public Research Center Henri Tudor, Luxembourg

  • Venue:
  • AST/UCMA/ISA/ACN'10 Proceedings of the 2010 international conference on Advances in computer science and information technology
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

A prerequisite to implement effective and efficient Information Systems security measures is to have a clear understanding of both, the business that the system will support and the importance of the system in the operating environment. Similarly, the evaluation of one's confidence in the deployed safeguarding measures, to adequately protect system assets, requires a better understanding of the security criticality of the system within its context of use (i.e. where is the system used and what for?). This paper proposes metrics as well as a methodology for the evaluation of operational systems security assurance. A critical feature of our approach is that assurance level is dependent on the measurement of security correctness and system security criticality. To that extend, we also propose a novel classification scheme for Information Systems based on their security criticality. Our work is illustrated with an application based on the case study of a Domain Name Server (DNS).