Authors:
Moussa Ouedraogo
1
;
Chien-Ting Kuo
2
;
Simon Tjoa
3
;
David Preston
4
;
Eric Dubois
1
;
Paulo Simoes
5
and
Tiago Cruz
5
Affiliations:
1
Public research Centre Henri Tudor, Luxembourg
;
2
Department of Electrical Engineering, National Taiwan University, 106 Taipei, Taiwan and Institute for Information Industry, Taiwan
;
3
St. Poelten University of Applied Sciences, Austria
;
4
University of East London, United Kingdom
;
5
University of Coimbra, Portugal
Keyword(s):
Security Assurance, Verification of Security, Security Management.
Related
Ontology
Subjects/Areas/Topics:
Data and Application Security and Privacy
;
Information and Systems Security
;
Security in Information Systems
;
Security Management
;
Security Metrics and Measurement
Abstract:
Despite the incommensurable effort made from across computer sciences disciplines to provide more secure systems, compromising the security of a system has now become a very common and stark reality for organizations of all sizes and from a variety of sectors. The lax in the technology has often been cited as the salient cause of systems insecurity. In this paper we advocate the need for a Security Assurance (SA) system to be embedded within current IT systems. Such a system has the potential to address one facet of cyber insecurity, which is the exploit of lax within the deployed security and its underlining policy. We discuss the challenges associated to such an SA assessment and present the flavor of its evaluation and monitoring through an initial prototype. By providing indicators on the status of a security matter that is more and more devolved to the provider as it is the case in the cloud, the SA tool can be used as a means of fostering better security transparency between a
cloud provider and client.
(More)