Information security is a main concern in many fields of computer and information technologies, from software development, or network systems, to new or emerging technologies such as mobile, cloud computing, or social computing. Existing security standards and models usually focus on "what" has to be done about security, but they do not propose "how" to deal with the inherent complexity of assuring modern software systems or network infrastructures. Application of current security standards usually produce large check lists describing security countermeasures, but they lack a structured, in-depth and consistent process to define the information security requirements at different granularity levels of the system. As a consequence, security deployments may miss important security controls. We propose the Infosec-tree Model, a novel methodology with a hierarchical approach to guide that comprehensive assurance process for a computer or network system. Real use cases are presented, by applying our methodology to assure a private cloud being developed at the Universidad de Costa Rica (UCR).
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.
customersupport@researchsolutions.com
10624 S. Eastern Ave., Ste. A-614
Henderson, NV 89052, USA
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Copyright © 2024 scite LLC. All rights reserved.
Made with 💙 for researchers
Part of the Research Solutions Family.