Assessing and Managing Quality of Information Assurance
Partha Pratim Pal, Patrick Hurley · 2010
The connection of coalition systems has many challenges, one of the most important and the one being address by this paper is the lack of understanding of information assurance (IA) in a coalition environment. This paper presents an approach to managing this coalition IA risk using a taxonomy to organize readily available observations and measurements that are potential indicators of a system's level of information assurance (IA). This paper also describes how this taxonomy can be used for runtime mission-oriented assessment and management of IA assets. In this context, a mission refers to a specific set of tasks carried out using the system by a group of users cooperating towards achieving a common objective, and IA refers to the users ' level of confidence that the system can be entrusted with their respective tasks. Modern information systems routinely incorporate security mechanisms such as firewalls, antivirus scanning tools and mechanisms for user authentication and authorization. Advanced mission-critical systems often incorporate security mechanisms aimed to maintain mission-specific security requirements (expressed in terms of availability, integrity and confidentiality) organized in a coherent manner that facilitates defense in