Trends in security evaluations
Jan Pieters · Proceedings of SPIE, the International Society for Optical Engineering/Proceedings of SPIE · 1996
Security evaluations are carried out for several reasons. They can be used for product improvement, in a risk analysis, or they can be used to verify the security claims or targets. Using a simplified design process scheme it is explained where, and to what extent security evaluations can be useful. Depending on the anticipated risk, or the trust the parties involved (manufacturers, users, or issuers) have in certain security related products, different sorts of evaluation can be carried out. The goals and the assumptions made for the different sorts of evaluation are discussed, as well as the relation between the sorts of evaluation. An important tool in evaluating security systems is the matrix security model. This model is discussed in some detail.