科技报告详细信息
Model-Based Assurance of Security Controls
Beres, Yolanta ; Baldwin, Adrian ; Shiu, Simon
HP Development Company
关键词: compliance;    assurance;    security;    audit;    metrics;   
RP-ID  :  HPL-2008-7
学科分类:计算机科学(综合)
美国|英语
来源: HP Labs
PDF
【 摘 要 】

The paper presents an innovative way to assess the effectiveness of security controls where measurable aspects of controls are first captured in the models and then the models are used to analyse the security data gathered from the IT environment. The aim is to lift the risk and security control management lifecycle from a series of people based processes to one where model based technology enhances, connects and where appropriate automates the process. Modelling in such an approach means capturing the relationship between controls and the way the controls should be measured for effectiveness and compliance to regulations and internal policies. This paper also describes how the model based assurance approach has been applied to automate the analysis of critical security controls during several IT application audits. We show advantages both in time savings due to automation of audit testing and in improvement of the control coverage due to the reduction in sampling. 6 Pages

【 预 览 】
附件列表
Files Size Format View
RO201804100002456LZ 354KB PDF download
  文献评价指标  
  下载次数:22次 浏览次数:52次