DocumentCode :
1953019
Title :
Option Based Evaluation: Security Evaluation of IT Products Based on Options Theory
Author :
Abbas, Haider ; Yngström, Louise ; Hemani, Ahmed
Author_Institution :
Electron., Comput. & Software Syst., R. Inst. of Technol., Stockholm, Sweden
fYear :
2009
fDate :
7-8 Sept. 2009
Firstpage :
134
Lastpage :
141
Abstract :
Reliability of IT systems and infrastructure is a critical need for organizations to trust their business processes. This makes security evaluation of IT systems a prime concern for these organizations. Common Criteria is an elaborate, globally accepted security evaluation process that fulfills this need. However CC rigidly follows the initial specification and security threats and takes too long to evaluate and as such is also very expensive. Rapid development in technology and with it the new security threats further aggravates the long evaluation time problem of CC to the extent that by the time a CC evaluation is done, it may no longer be valid because new security threats have emerged that have not been factored in. To address these problems, we propose a novel Option Based Evaluation methodology for security of IT systems that can also be considered as an enhancement to the CC process. The objective is to address uncertainty issues in IT environment and speed up the slow CC based evaluation processes. OBE will follow incremental evaluation model and address the following main concerns based on options theory i.e. i) managing dynamic security requirement with mid-course decision management ii) devising evaluation as an improvement process iii) reducing cost and time for evaluation of an IT product.
Keywords :
information technology; security of data; IT products; IT system security; common criteria evaluation process; incremental evaluation model; mid-course decision management; option based evaluation methodology; options theory; security evaluation; security threats; Computer security; Costs; Finance; Gas industry; Investments; Petroleum; Reliability engineering; Reliability theory; Software systems; Uncertainty; Real Options Analysis; Security Evaluation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Engineering of Computer Based Systems, 2009. ECBS-EERC '09. First IEEE Eastern European Conference on the
Conference_Location :
Novi Sad
Print_ISBN :
978-1-4244-4677-3
Electronic_ISBN :
978-0-7695-3759-7
Type :
conf
DOI :
10.1109/ECBS-EERC.2009.27
Filename :
5290981
Link To Document :
بازگشت