Evaluation, Security

Christopher Alberts · Encyclopedia of Software Engineering · 2002

Abstract Security evaluation is a broad term that encompasses diverse subjects, from product and system certification to an organization's operational security risk (Summers, 1997). Four common types of security evaluations are 1. Security evaluations of products and systems against evaluation criteria (standards); 2. Information systems audits; 3. Vulnerability evaluations; 4. Information security risk evaluations, there four types are the subjects of this article. Standards define criteria to help assure users and stakeholders that a product or system provides a defined level of security. Security evaluations against these criteria help ensure that products and systems meet their information technology security objectives and requirements. The other three types of evaluation—information systems audits, vulnerability evaluations, and information security risk evaluations—take into account the operational environment of organizations that use information technology. These evaluations focus on how organizations use information technology products and systems in their day‐to‐day operations. Information systems auditing is an independent appraisal of an organization's internal controls to assure management, regulatory authorities, and company shareholders that information is accurate and valid. Vulnerability and risk evaluations are performed by information security specialists and are often driven by an organization's management as part of a security improvement initiative. A vulnerability evaluation examines organizational policies and procedures, administrative controls, internal controls, implementation of technology, and physical layout for weaknesses. An information security risk evaluation also focuses on an organization's operational environment by examining organizational policies and practices as well as the installed technology base to identify risks to an organization's important information assets. As information security risk evaluation focuses on the following three items: an organization's important assets, the threats to the assets, and the vulnerabilities that expose the asset to the threats. Thus, a vulnerability evaluation is a subset of an information security risk evaluation.

Read the paper · More papers on PaperTik