首页> 美国政府科技报告 >Methodology, a Language, and a Tool to Provide Information Security Assurance Arguments.
【24h】

Methodology, a Language, and a Tool to Provide Information Security Assurance Arguments.

机译:方法,语言和提供信息安全保障参数的工具。

获取原文

摘要

As information systems become more complex and industry and military rely more on their correct operation, the need for survivable, secure systems becomes more pressing. System designers and assessors need to clearly understand the causality, relationships, vulnerabilities, threats, system-level view points, and objectives of an entire enterprise. To design a system that can be trusted or assess security properties in a system, the related assurance arguments need to be developed and described effectively in a well-organized format by means of a sound language. To satisfy this requirement, we introduce a methodology, ECM (Enterprise Certification Methodology), to derive and organize the related assurance arguments effectively. We have developed a visual language, CAML (Composite Assurance Mapping language), to build the map of the assurance argument using ECM. This map depicts the claim trees for the assurance arguments related to the enterprise security objective. We have also developed a tool, VRNM (Visual Network Rating Methodology), to help users develop a map to assurance arguments in CAML based on 11CM and document it with related descriptions in a common environment.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号