首页> 外文会议>7th International IET System Safety Conference, incorporating the Cyber Security Conference 2012. >What does the Assurance Case Approach deliver for Critical Information Infrastructure Protection in cybersecurity?
【24h】

What does the Assurance Case Approach deliver for Critical Information Infrastructure Protection in cybersecurity?

机译:确保案例方法为网络安全中的关键信息基础架构保护提供了什么?

获取原文
获取原文并翻译 | 示例

摘要

This paper describes how the Assurance Case Approach (ACA) was applied for Cyber Security and Critical National Infrastructure resilience, using for a single asset an individual Assurance Case (AC), and for system-of-systems clustering a `Mesh' case concept. Despite its common use in the Safety domain, the ACA concept had not been applied to a dynamic situation. It allowed for Cases to be clustered using a `Mesh' Case to summarise a particular ecosystem/environment. This ACA is defined using basic elements of an assurance case ie Claim, argument and evidence - often associated with a legal analogy. Using the case study research method [27], the main methodology as stated in the paper combined the organisational learning cycle [1] with the 6-step based process based on a GSN [16] and CAE [2] notational hybrid for the construction of an argument structure. This was implemented with a CII asset, and further pilotted to demonstrate the ACA for other CII nodes [13]. The clustering using the `Mesh' cases closely aligns with Interdependency Analysis for the UK interconnected system-of-systems. Further work is required to expand the `Mesh' case principle for the 21st century information-centric ecosystem to provide a continual resilience work process framework, which eventually must include real-time inputs.
机译:本文描述了保证案例方法(ACA)如何应用于网络安全和关键的国家基础设施弹性,如何针对单个资产使用单个保证案例(AC),以及如何将“网状”案例概念聚类到系统系统中。尽管ACA概念在安全领域中得到了普遍使用,但它并未应用于动态情况。它允许案例使用“网格”案例进行聚类以总结特定的生态系统/环境。此ACA是使用保证案例的基本要素定义的,即索赔,论点和证据-通常与法律类比相关联。使用案例研究方法[27],本文所述的主要方法将组织学习周期[1]与基于GSN [16]和CAE [2]符号混合的6步过程相结合进行构建参数结构。这是通过CII资产实现的,并进一步试点以演示其他CII节点的ACA [13]。使用“ Mesh”案例的聚类与英国互连的系统间体系的相互依赖性分析紧密相关。需要进一步的工作来扩展21世纪以信息为中心的生态系统的“网格”案例原则,以提供一个持续的弹性工作流程框架,该框架最终必须包括实时输入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号