Title :
Operational security assurance evaluation in open infrastructures
Author :
Haddad, Sammy ; Dubus, Samuel ; Hecker, Artur ; Kanstrén, Teemu ; Marquet, Bertrand ; Savola, Reijo
Author_Institution :
Telecom ParisTech, Oppida, France
Abstract :
Measuring and evaluating cyber security is of primary importance in IT systems. The fundamental need to assess security choices validity and effectiveness is growing. One of the main accepted approaches to this problem is a standardized offline security assurance evaluation. But, this method is static, time consuming and does not scale well to complex and dynamic Telco systems. As such, it does not apply to a continuous security assurance assessment for today´s complex operational systems. In this paper, we present a methodology together with the required tools for the operational security assurance assessment of Telco services. Our methodology enables (i) the definition and instantiation of a security Assurance Profile, and (ii) the use of a flexible measurement framework and a security cockpit for operational assurance metrics evaluation. The Assurance Profile provides a framework to the security expert community in order to collect descriptions and architectures of typical security mechanisms, and establish best practices on operational security assurance requirements and measurements for these architectures. The distributed dedicated measurement framework and the security assurance cockpit, as integral parts of the operational assurance assessment process, provide specifically adapted tools to evaluate operational security assurance on targeted systems.
Keywords :
information systems; security of data; IT system; Telco service; continuous security assurance assessment; cyber security; open infrastructure; operational assurance assessment process; operational security assurance assessment; operational security assurance evaluation; operational security assurance requirement; security assurance cockpit; security assurance profile; standardized offline security assurance evaluation; Computer architecture; Measurement; Probes; Risk analysis; Security; Software; Standards;
Conference_Titel :
Risk and Security of Internet and Systems (CRiSIS), 2011 6th International Conference on
Conference_Location :
Timisoara
Print_ISBN :
978-1-4577-1890-8
Electronic_ISBN :
978-1-4577-1889-2
DOI :
10.1109/CRiSIS.2011.6061831