Skip to main content
SHARE
Publication

Evaluating Security Controls Based on Key Performance Indicators and Stakeholder Mission...

by Frederick T Sheldon, Robert K Abercrombie, Ali Mili
Publication Type
Conference Paper
Book Title
ACM International Conference Proceeding Series
Publication Date
Page Number
1
Volume
288
Publisher Location
New York, New Jersey, United States of America
Conference Name
4th Annual Cyber Security and Information Intelligence Workshop
Conference Location
Oak Ridge, Tennessee, United States of America
Conference Sponsor
ORNL CSED, Association of Computing Machinery (ACM), and EUROSIS
Conference Date
-

Good security metrics are required to make good decisions about how to design security countermeasures, to choose between alternative security architectures, and to improve security during operations. Therefore, in essence, measurement can be viewed as a decision aid. The lack of sound practical security metrics is severely hampering progress in the development of secure systems.
The Cyberspace Security Econometrics System (CSES) offers the following advantages over traditional measurement systems: (1) CSES reflects the variances that exist amongst different stakeholders of the same system. Different stakeholders will typically attach different stakes to the same
requirement or service (e.g., a service may be provided by an information technology system or process control system, etc.). (2) For a given stakeholder, CSES reflects the variance that may exist among the stakes she/he attaches to meeting each requirement. The same stakeholder may attach
different stakes to satisfying different requirements within the overall system specification. (3) For a given compound specification (e.g., combination(s) of
commercial off the shelf software and/or hardware), CSES reflects the variance that may exist amongst the levels of verification and validation (i.e., certification) performed on components of the specification. The certification activity may produce higher levels of assurance across different components of the specification than others. Consequently, this paper introduces the basis, objectives and capabilities for the CSES including inputs/outputs and the basic
structural and mathematical underpinnings.