Research literature has argued the need for a methodology to measure security assurance levels of a system as vital in order to maintain and improve the overall system security. This paper proposes a risk-based security assurance metric and aggregation techniques to be incorporated in a methodology for the evaluation of IT systems security assurance.
Published in:
Communication Networks and Services Research Conference, 2009. CNSR '09. Seventh Annual
Date of Conference: 11-13 May 2009