A Framework for Reasoning about Assurance
نویسندگان
چکیده
Informed decisions about security depend upon a complex set of factors related to both assurance and risk. In this paper we argue for a new definition of assurance, specifically describing its relationship to measurements of risk or security. The following definition expands the traditional definition of assurance to include a broad range of evidence, while narrowing the scope to a specific type of confidence. Assurance is a measure of confidence in the accuracy of a risk or security measurement. This paper offers a way to build upon risk and security measurement methodologies and to employ them in such a way as to yield a rough measure of assurance. We do not advocate a particular method for measuring risk or security, but assume that such methodologies and tools are available. Consider the decision maker who must decide whether to accept a risk or make an investment to mitigate the problem. He may use a risk assessment tool to help quantify the risk, but he may have very little confidence that the numbers are accurate. In essence, he is not sure whether the risk is acceptable or not. Assurance is a major factor in security decisions. The decision maker has two options for handling such situations. If his confidence in the risk measurement is high, he can attempt to reduce risk by adding security mechanisms. If his confidence is low, however, adding another mechanism may not help. In fact, adding a new mechanism may even increase uncertainty in the risk measurement. In this case, the decision maker needs to improve assurance by obtaining better information about the severity of the risk. If the decision maker then decides to reduce this uncertainty, we offer a structure for assurance arguments as a logical way to communicate the information used in making security decisions. An assurance argument starts with claims about risks and then packages all the evidence and supporting arguments into a logical hierarchical structure. The goal is that these arguments will be capable of reuse in a wide variety of applications, easing the burden of security evaluations. Assurance arguments are a powerful tool to reduce the uncertainty in risk or security assessments. Although this paper does not provide a means by which one can determine assurance need in the sense of some quantitative or even qualitative statement, it does provide a way of deciding whether or not the assurance one has is sufficient, …
منابع مشابه
An enterprise assurance framework
This paper explores generating and conveying confidence in enterprise security. An enterprise assurance framework provides a structure enterprise assurance evidence that strengthens and clarifies the overall enterprise assurance argument. The structure and components of these arguments are defined and then applied to an enterprise. Finally, standards of evidence and evidence trade-offs are ment...
متن کاملHigh Assurance Software Development
The purpose of this paper is describe how to make software assurance a part of a science of security. Software assurance as practiced is a grab-bag of techniques, heuristics, and lessons learned from earlier failures. Given the importance of software to critical infrastructures (electricity, banking, medicine), this is an untenable situation; the smooth functioning of our society depends on thi...
متن کاملAn Integrated Framework for Multi-layer Certification- based Assurance
Complexity, dynamism and overlays in networks and systems are some of the main challenges we face nowadays when reasoning on systems’ assurance and behavior. Security certification has shown to be a solid foundation to provide assurance and trust about system properties. This paper presents a certification framework for composite, layered and evolving systems, such as cloud systems or cyber phy...
متن کاملPROPERTY ANALYSIS OF TRIPLE IMPLICATION METHOD FOR APPROXIMATE REASONING ON ATANASSOVS INTUITIONISTIC FUZZY SETS
Firstly, two kinds of natural distances between intuitionistic fuzzy sets are generated by the classical natural distance between fuzzy sets under a unified framework of residual intuitionistic implication operators. Secondly, the continuity and approximation property of a method for solving intuitionistic fuzzy reasoning are defined. It is proved that the triple implication method for intuitio...
متن کاملNormativeness, Relevance, and Temporality in Specifying and Reasoning about Information Security and Assurance: Can We have a Formal Logic System as a Unified Logical Basis?
This position paper points out the ‘NRT problem’ in specifying and reasoning about information security and assurance: Although it is necessary to deal with normative, relevance, and temporal notions explicitly and soundly in specifying and reasoning about information security and assurance, until now there is no formal logic system can be used as a unified logical basis for the purpose. Theref...
متن کاملA Device and Service Description Framework for Discovering and Reasoning in Autonomous P2P Environment
In this paper, we present a new service and device description framework in autonomous P2P environment. In couple of years, many ubiquitous oriented devices are coming into our life, which create peer-to-peer (P2P) network and work autonomously. When we do something inside such environment, we should discover the devices, and reason which one is most suitable for our objectives. We propose a ne...
متن کامل