Evaluating Security Assurance Case Adaptation

dc.contributor.authorJahan, Sharmin
dc.contributor.authorMarshall, Allen
dc.contributor.authorGamble, Rose
dc.date.accessioned2019-01-03T00:59:17Z
dc.date.available2019-01-03T00:59:17Z
dc.date.issued2019-01-08
dc.description.abstractSecurity certification processes for information systems involve expressing security controls as functional and non-functional requirements, monitoring deployed mechanisms that satisfy the requirements, and measuring the degree of confidence in system compliance. With the potential for systems to perform runtime self-adaptation, functional changes to remedy system performance may impact security control compliance. This impact can extend throughout a network of related controls causing significant degradation to the system’s overall compliance status. We represent security controls as security assurance cases and implement them in XML for management and evaluation. The approach maps security controls to softgoals, introducing achievement weights to the assurance case structure as the foundation for determining security softgoal satisficing levels. Potential adaptations adjust the achievement weights to produce different satisficing levels. We show how the levels can be propagated within the network of related controls to assess the overall security control compliance of a potential adaptation.
dc.format.extent10 pages
dc.identifier.doi10.24251/HICSS.2019.878
dc.identifier.isbn978-0-9981331-2-6
dc.identifier.urihttp://hdl.handle.net/10125/60168
dc.language.isoeng
dc.relation.ispartofProceedings of the 52nd Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCybersecurity and Software Assurance
dc.subjectSoftware Technology
dc.subjectSelf-adaptation, security control, security certification, assurance case, softgoal, achievement weight, satisficing
dc.titleEvaluating Security Assurance Case Adaptation
dc.typeConference Paper
dc.type.dcmiText

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0728.pdf
Size:
1.96 MB
Format:
Adobe Portable Document Format