1 / 7

UNCLASSIFIED Security Metrics: Examples

UNCLASSIFIED Security Metrics Computer System Security & Privacy Advisory Board June 13-14, 2000 Dr. Stuart Katzke Chief Scientist, Information Assurance Solutions Group National Security Agency (410) 854-7308 swkatzk@missi.ncsc.mil UNCLASSIFIED. UNCLASSIFIED Security Metrics: Examples.

maep
Download Presentation

UNCLASSIFIED Security Metrics: Examples

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. UNCLASSIFIEDSecurity MetricsComputer System Security & Privacy Advisory BoardJune 13-14, 2000Dr. Stuart KatzkeChief Scientist, Information Assurance Solutions GroupNational Security Agency(410) 854-7308swkatzk@missi.ncsc.milUNCLASSIFIED

  2. UNCLASSIFIEDSecurity Metrics: Examples • Measuring the effectiveness of a security program • Measuring an organizations/individuals ability to do security engineering & security assessment • Measuring how secure a system/product is • Measuring how good a security method/approach is • Measuring risk UNCLASSIFIED

  3. UNCLASSIFIEDSecurity Metrics • Ambiguous • Immature Discipline • Uncertainty • Lack Precision • Good Examples Exist • FIPS 140 • TCSEC (Orange Book) • Sometimes Use IndirectMeasurement Methods (e.g., process as indicator) UNCLASSIFIED

  4. UNCLASSIFIEDSecurity Metrics: Model • ? • direct/indirect • assurance/confidence Security Objectives (SOs) • Object Metrics UNCLASSIFIED

  5. UNCLASSIFIEDSecurity Metrics: Model • Object • product • system • vpn • intranet • e-business • security program • professional competence • individual • organization • UNCLASSIFIED • ? (direct/indirect) • testing • functional • red team/penetration • green team • evaluation • assessment • risk/vulnerability • effectiveness • accreditation • training/education/competence • observation of performance (e.g., intrusion detection) • SOs • requirements • CC PPs • specs/stds • control objectives • best practice • baseline • due diligence • maturity models • SSE-CMM • IA-CMM Metrics

  6. UNCLASSIFIEDSecurity Metrics (Who: Object; Description) • CSSPAB: CS Program; Effectiveness Assessment • CIO Council: CS Program; Maturity Framework • Private Sector: Organization; SSE-Capability Maturity Model • NIAP: Organization; Infosec Assessment-Capability Maturity Model • NIAP: Individual; Infosec Assessment Methodology (Ability/Capability) UNCLASSIFIED

  7. UNCLASSIFIEDSecurity Metrics: Activities (cont.)(Who: Object; Description) • NSA: Individual; Infosec System Security Engineering • Many Sources: Products; Protection Profiles (Smartcard, Firewalls, VPNs, OS) • BITS: Products; PP-like functional specification • CIO Council: Organization; IT Privacy Impact Assessment (Draft: IRS Model) • DoD: Organization; Infosec Assurance Readiness Metrics (Draft: self assessment/check list) UNCLASSIFIED

More Related