Security Assurance Metrics and Aggregation Techniques for IT Systems
Moussa Ouedraogo, Haralambos Mouratidis, Djamel Khadraoui, Éric Dubois · 2009
Research literature has argued the need for a methodology to measure security assurance levels of a system as vital in order to maintain and improve the overall system security. Building on our close examination of the existing approaches for IT Information assurance, this paper proposes a risk-based security assurance metrics and aggregation techniques to be incorporated in a methodology for the evaluation of IT systems security assurance.