首页> 外文OA文献 >A probe quality metric taxonomy for assurance evaluation
【2h】

A probe quality metric taxonomy for assurance evaluation

机译:用于保证评估的探针质量度量分类法

摘要

Commonly, assurance is considered as "something said or done to inspire confidence". Itis clear from this definition that the fundamental part of assurance is confidence. However, the levelof confidence inspired from a statement or an action depends on the ―quality‖ of its source. Inspiredby the Systems Security Engineering Capability Maturity Model (SSE-CMM) and the CommonCriteria, we tailored five ordinal levels of quality levels for probes performing the verification ofsystem security measures; different levels of quality being possible depending on the coverage, rigor,depth and Independence of the verification. The metric taxonomy is intended to assist IT Productsmanufacturers in developing their products or systems and in identifying security requirements to besatisfied for their products or systems to be assured at some level of quality as far as assuranceevaluation is concerned. It could also benefit consumers in supporting them in selecting IT securityproducts depending on their organizational needs, while IT security evaluators may use it as referencewhen forming judgments about the quality of a security product.
机译:通常,保证被认为是“为了激发信心而说或做的事情”。从这个定义可以明显看出,保证的基本部分是信心。但是,从陈述或行动中获得的信心水平取决于其来源的“质量”。受系统安全工程能力成熟度模型(SSE-CMM)和CommonCriteria的启发,我们为执行系统安全性措施验证的探针定制了五个有序的质量级别;根据验证的覆盖范围,严谨性,深度和独立性,可以实现不同级别的质量。度量标准分类法旨在帮助IT产品制造商开发其产品或系统,并确定就其质量或某种程度的安全性而言要满足的安全性要求,以保证评估为准。它还可以使消费者受益,可以根据他们的组织需求支持他们选择IT安全产品,而IT安全评估人员在对安全产品的质量做出判断时可以将其用作参考。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号