Vis enkel innførsel

dc.contributor.authorWen, Shao-Fang
dc.contributor.authorKatt, Basel
dc.date.accessioned2023-11-17T11:06:52Z
dc.date.available2023-11-17T11:06:52Z
dc.date.created2023-10-03T13:42:17Z
dc.date.issued2023
dc.identifier.issn2056-4961
dc.identifier.urihttps://hdl.handle.net/11250/3103185
dc.description.abstractPurpose Security assurance evaluation (SAE) is a well-established approach for assessing the effectiveness of security measures in systems. However, one aspect that is often overlooked in these evaluations is the assurance context in which they are conducted. This paper aims to explore the role of assurance context in system SAEs and proposes a conceptual model to integrate the assurance context into the evaluation process. Design/methodology/approach The conceptual model highlights the interrelationships between the various elements of the assurance context, including system boundaries, stakeholders, security concerns, regulatory compliance and assurance assumptions and regulatory compliance. Findings By introducing the proposed conceptual model, this research provides a framework for incorporating the assurance context into SAEs and offers insights into how it can influence the evaluation outcomes. Originality/value By delving into the concept of assurance context, this research seeks to shed light on how it influences the scope, methodologies and outcomes of assurance evaluations, ultimately enabling organizations to strengthen their system security postures and mitigate risks effectively.en_US
dc.language.isoengen_US
dc.publisherEmeralden_US
dc.rightsNavngivelse 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/deed.no*
dc.titleExploring the role of assurance context in system security assurance evaluation: a conceptual modelen_US
dc.title.alternativeExploring the role of assurance context in system security assurance evaluation: a conceptual modelen_US
dc.typePeer revieweden_US
dc.typeJournal articleen_US
dc.description.versionacceptedVersionen_US
dc.source.journalInformation and Computer Securityen_US
dc.identifier.doi10.1108/ICS-06-2023-0101
dc.identifier.cristin2181344
cristin.ispublishedtrue
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel

Navngivelse 4.0 Internasjonal
Med mindre annet er angitt, så er denne innførselen lisensiert som Navngivelse 4.0 Internasjonal