Evaluating Security Assurance Case Adaptation

dc.contributor.author Jahan, Sharmin
dc.contributor.author Marshall, Allen
dc.contributor.author Gamble, Rose
dc.date.accessioned 2019-01-03T00:59:17Z
dc.date.available 2019-01-03T00:59:17Z
dc.date.issued 2019-01-08
dc.description.abstract Security certification processes for information systems involve expressing security controls as functional and non-functional requirements, monitoring deployed mechanisms that satisfy the requirements, and measuring the degree of confidence in system compliance. With the potential for systems to perform runtime self-adaptation, functional changes to remedy system performance may impact security control compliance. This impact can extend throughout a network of related controls causing significant degradation to the system’s overall compliance status. We represent security controls as security assurance cases and implement them in XML for management and evaluation. The approach maps security controls to softgoals, introducing achievement weights to the assurance case structure as the foundation for determining security softgoal satisficing levels. Potential adaptations adjust the achievement weights to produce different satisficing levels. We show how the levels can be propagated within the network of related controls to assess the overall security control compliance of a potential adaptation.
dc.format.extent 10 pages
dc.identifier.doi 10.24251/HICSS.2019.878
dc.identifier.isbn 978-0-9981331-2-6
dc.identifier.uri http://hdl.handle.net/10125/60168
dc.language.iso eng
dc.relation.ispartof Proceedings of the 52nd Hawaii International Conference on System Sciences
dc.rights Attribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.uri https://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subject Cybersecurity and Software Assurance
dc.subject Software Technology
dc.subject Self-adaptation, security control, security certification, assurance case, softgoal, achievement weight, satisficing
dc.title Evaluating Security Assurance Case Adaptation
dc.type Conference Paper
dc.type.dcmi Text
Files
Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
0728.pdf
Size:
1.96 MB
Format:
Adobe Portable Document Format
Description: