Show simple item record

dc.contributor.authorShukla, Ankur
dc.contributor.authorKatt, Basel
dc.contributor.authorNweke, Livinus Obiora
dc.contributor.authorYeng, Prosper
dc.contributor.authorWeldehawaryat, Goitom Kahsay
dc.date.accessioned2022-09-23T11:11:00Z
dc.date.available2022-09-23T11:11:00Z
dc.date.created2022-09-21T05:55:12Z
dc.date.issued2022
dc.identifier.issn1574-0137
dc.identifier.urihttps://hdl.handle.net/11250/3020902
dc.description.abstractSystem security assurance provides the confidence that security features, practices, procedures, and architecture of software systems mediate and enforce the security policy and are resilient against security failure and attacks. Alongside the significant benefits of security assurance, the evolution of new information and communication technology (ICT) introduces new challenges regarding information protection. Security assurance methods based on the traditional tools, techniques, and procedures may fail to account new challenges due to poor requirement specifications, static nature, and poor development processes. The common criteria (CC) commonly used for security evaluation and certification process also comes with many limitations and challenges. In this paper, extensive efforts have been made to study the state-of-the-art, limitations and future research directions for security assurance of the ICT and cyber–physical systems (CPS) in a wide range of domains. We conducted a systematic review of requirements, processes, and activities involved in system security assurance including security requirements, security metrics, system and environments and assurance methods. We highlighted the challenges and gaps that have been identified by the existing literature related to system security assurance and corresponding solutions. Finally, we discussed the limitations of the present methods and future research directions.en_US
dc.language.isoengen_US
dc.publisherElsevieren_US
dc.rightsNavngivelse 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/deed.no*
dc.titleSystem security assurance: A systematic literature reviewen_US
dc.title.alternativeSystem security assurance: A systematic literature reviewen_US
dc.typePeer revieweden_US
dc.typeJournal articleen_US
dc.description.versionpublishedVersionen_US
dc.source.journalComputer Science Reviewen_US
dc.identifier.doihttps://doi.org/10.1016/j.cosrev.2022.100496
dc.identifier.cristin2053716
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record

Navngivelse 4.0 Internasjonal
Except where otherwise noted, this item's license is described as Navngivelse 4.0 Internasjonal