Exploring the role of assurance context in system security assurance evaluation: a conceptual model
Purpose Security assurance evaluation (SAE) is a well-established approach for assessing the effectiveness of security measures in systems. However, one aspect that is often overlooked in these evaluations is the assurance context in which they are conducted. This paper aims to explore the role of assurance context in system SAEs and proposes a conceptual model to integrate the assurance context into the evaluation process. Design/methodology/approach The conceptual model highlights the interrelationships between the various elements of the assurance context, including system boundaries, stakeholders, security concerns, regulatory compliance and assurance assumptions and regulatory compliance. Findings By introducing the proposed conceptual model, this research provides a framework for incorporating the assurance context into SAEs and offers insights into how it can influence the evaluation outcomes. Originality/value By delving into the concept of assurance context, this research seeks to shed light on how it influences the scope, methodologies and outcomes of assurance evaluations, ultimately enabling organizations to strengthen their system security postures and mitigate risks effectively.
Year of publication: |
2023
|
---|---|
Authors: | Wen, Shao-Fang ; Katt, Basel |
Published in: |
Information & Computer Security. - Emerald Publishing Limited, ISSN 2056-497X, ZDB-ID 2810936-3. - Vol. 32.2023, 2, p. 159-178
|
Publisher: |
Emerald Publishing Limited |
Subject: | System security | Security assurance | Security evaluation | Context model |
Saved in:
Online Resource
Saved in favorites
Similar items by subject
-
Zadahmad, Manouchehr, (2016)
-
Exploring the Influence of Contexts for Mobile Recommendation
Zeng, Jun, (2017)
-
Evaluation on Land Ecological Security in Hainan Island
Wang, Jun-guang, (2009)
- More ...