首页> 外文会议>2018 IEEE International Workshop on Metrology for Industry 4.0 and IoT >Coverage-Based Heuristics for Selecting Assessment Items from Security Standards: A Core Set Proposal
【24h】

Coverage-Based Heuristics for Selecting Assessment Items from Security Standards: A Core Set Proposal

机译:从安全标准中选择评估项目的基于覆盖的启发式方法:核心集提议

获取原文
获取原文并翻译 | 示例

摘要

In the realm of Internet of Things (IoT), information security is a critical issue. Security standards, including their assessment items, are essential instruments in the evaluation of systems security. However, a key question remains open: “Which test cases are most effective for security assessment?” To create security assessment designs with suitable assessment items, we need to know the security properties and assessment dimensions covered by a standard. We propose an approach for selecting and analyzing security assessment items; its foundations come from a set of assessment heuristics and it aims to increase the coverage of assessment dimensions and security characteristics in assessment designs. The main contribution of this paper is the definition of a core set of security assessment heuristics. We systematize the security assessment process by means of a conceptual formalization of the security assessment area. Our approach can be applied to security standards to select or to prioritize assessment items with respect to 11 security properties and 6 assessment dimensions. The approach is flexible allowing the inclusion of dimensions and properties. Our proposal was applied to a well know security standard (ISO/IEC 27001) and its assessment items were analyzed. The proposal is meant to support: (i) the generation of high-coverage assessment designs, which include security assessment items with assured coverage of the main security characteristics, and (ii) evaluation of security standards with respect to the coverage of security aspects.
机译:在物联网(IoT)领域,信息安全是一个关键问题。安全标准,包括其评估项目,是评估系统安全性的基本工具。但是,仍然存在一个关键问题:“哪个测试用例对安全性评估最有效?”要创建具有适当评估项目的安全评估设计,我们需要了解标准涵盖的安全属性和评估范围。我们提出了一种选择和分析安全评估项目的方法;它的基础来自一组评估启发式方法,旨在扩大评估设计中评估维度和安全性特征的覆盖范围。本文的主要贡献是定义了一组核心的安全评估启发式方法。我们通过对安全评估领域进行概念化的形式化来对安全评估过程进行系统化。我们的方法可以应用于安全标准,以针对11个安全属性和6个评估维度选择评估项目或确定评估项目的优先级。该方法是灵活的,允许包含尺寸和属性。我们的建议被应用于众所周知的安全标准(ISO / IEC 27001),并分析了其评估项目。该提案旨在支持:(i)生成高覆盖率的评估设计,其中包括对主要安全特征有保证的覆盖范围的安全评估项目,以及(ii)关于安全方面的覆盖范围的安全标准评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号