Towards a security evaluation model based on security metrics
Jakub Breier, Ladislav Hudec · 2012
Methods for risk evaluation often involve subjective criteria because this process is undertaken by a risk analyst influenced by his own knowledge and experience. The purpose of this work is to bring objectivity to this process and to provide a discrete-scale evaluation of implemented security controls. It provides results and a final score from a security attributes point of view, that is a quality ranking of confidentiality, integrity, availability, authenticity and non-repudiability within the organization. The assignment of security clauses from the ISO/IEC 27002:2005 standard to security attributes uses the Formal Concept Analysis method, which provides summarized and clear object-attribute classification.