Quantitative evaluation of information system security

Rodolphe Ortalo, Yves Deswarte · International Conference on Information Security · 1998

This paper presents a method for the evaluation of the security of information systems. First, we outline briefly the overall guidelines of the method: specification of the security policy, description of the vulnerabilities of the target organization, and a quantitative evaluation approach based on the privilege graph model. Then, the paper presents how the method applies to the description of the security requirements of a real organization: a medium-size bank agency. To illustrate the interest of the security measures, this example is used as a basis for applying the evaluation methodology taking into account some vulnerabilities of the bank agency.

Read the paper · More papers on PaperTik