Security Assurance Evaluation and IT Systems' Context of Use Security Criticality

  • Authors:
  • Moussa Ouedraogo;Haralambos Mouratidis;Eric Dubois;Djamel Khadraoui

  • Affiliations:
  • Public Research Center Henri Tudor, Luxembourg;University of East London, England;Public Research Center Henri Tudor, Luxembourg;Public Research Center Henri Tudor, Luxembourg

  • Venue:
  • International Journal of Handheld Computing Research
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Today's IT systems are ubiquitous and take the form of small portable devices, to the convenience of the users. However, the reliance on this technology is increasing faster than the ability to deal with the simultaneously increasing threats to information security. This paper proposes metrics and a methodology for the evaluation of operational systems security assurance that take into account the measurement of security correctness of a safeguarding measure and the analysis of the security criticality of the context in which the system is operating i.e., where is the system used and/or what for?. In that perspective, the paper also proposes a novel classification scheme for elucidating the security criticality level of an IT system. The advantage of this approach lies in the fact that the assurance level fluctuation based on the correctness of deployed security measures and the criticality of the context of use of the IT system or device, could provide guidance to users without security background on what activities they may or may not perform under certain circumstances. This work is illustrated with an application based on the case study of a Domain Name Server DNS.