By surveying verification, validation, and evaluation methods referenced in information security risk management (ISRM) literature, the authors discuss in which ISRM phases particular methods should be applied and demonstrate appropriate methods with a real-world example.
Published in:
Security & Privacy, IEEE
(Volume:9
,
Issue:
2
)
Date of Publication: March-April 2011