Development of Supporting Environment for IT System Security Evaluation Based on ISO/IEC 15408 and ISO/IEC 18045

被引:1
|
作者
Bao, Da [1 ]
Sun, Wen [1 ]
Goto, Yuichi [1 ]
Cheng, Jingde [1 ]
机构
[1] Saitama Univ, Dept Informat & Comp Sci, Saitama 3388570, Japan
关键词
ISO/IEC; 15048; 18045; information technology; security evaluation; information security evaluation;
D O I
10.1109/SmartWorld.2018.00070
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
ISO/IEC 15408 and ISO/IEC 18045 are a pair of international competitive standards for security evaluation and certification of IT systems. Evaluation based on ISO/IEC 15408 and ISO/IEC 18045 is a very complex process that involves tens of documents and tasks. Performing the tasks in evaluation process by human costs a lot of time and it is also difficult to ensure impartial and no subjective mistakes. These issues not only result in consuming a lot of time, but also affect the fairness, correctness and accuracy of evaluation results. A supporting environment was proposed to provide necessary software tools to supports all tasks in the evaluation process automatically to ensure the quality of evaluation resultsat the same time reduce the complexity of all evaluator and certifiers' work. To provide full facilities of the supporting environment, we must clarify every task in the evaluation process and provide appropriate methods for developing supporting tools. This paper deeply analyzes all of the software supportable tasks in the evaluation process and clarifies all detail targets for each task. And then we also provide corresponding methods to support these tasks. This paper also shows a set of developed supporting tools that can perform the evaluation tasks in an organized way.
引用
收藏
页码:204 / 209
页数:6
相关论文
共 50 条
  • [31] NEW STANDARD ISO/IEC 27001:2013 OF INFORMATION SECURITY MANAGEMENT SYSTEM
    Drastich, Martin
    [J]. KNOWLEDGE FOR MARKET USE 2014: MEDIA AND COMMUNICATION IN THE 21ST CENTURY, 2014, : 387 - 393
  • [32] A Model of an Information Security Management System Based on NTC-ISO/IEC 27001 Standard
    Fonseca-Herrera, Omar A.
    Rojas, Alix E.
    Florez, Hector
    [J]. IAENG International Journal of Computer Science, 2021, 48 (02) : 1 - 10
  • [33] Development of an Automotive Regulatory Requirements Management System Based on ISO/IEC/IEEE 29148
    Martins, Henrique R.
    Fahy, James
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON ELECTRO/INFORMATION TECHNOLOGY (EIT), 2018, : 939 - 944
  • [34] Security Characteristic Evaluation Based On ISO/IEC 25023 Quality Model, Case Study: Laboratory Management Information System
    Aziz, M. Nasrul
    Sapta, Irit Maulana
    Rochimah, Siti
    [J]. 2018 ELECTRICAL POWER, ELECTRONICS, COMMUNICATIONS, CONTROLS, AND INFORMATICS SEMINAR (EECCIS), 2018, : 332 - 336
  • [35] Information Security Management Systems - A Maturity Model Based on ISO/IEC 27001
    Proenca, Diogo
    Borbinha, Jose
    [J]. BUSINESS INFORMATION SYSTEMS (BIS 2018), 2018, 320 : 102 - 114
  • [36] Analysis of ISO/IEC 17799:2000 to be used in Security Metrics
    Villarrubia, C
    Fernández-Medina, E
    Piattini, M
    [J]. SAM '04: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, 2004, : 109 - 117
  • [37] Modeling Dependencies of ISO/IEC 27002:2013 Security Controls
    Sengupta, Anirban
    [J]. SECURITY IN COMPUTING AND COMMUNICATIONS (SSCC 2015), 2015, 536 : 354 - 367
  • [38] A Comparative Review of Cloud Security Proposals with ISO/IEC 27002
    Rebollo, Oscar
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    [J]. WOSIS 2011: SECURITY IN INFORMATION SYSTEMS, 2011, : 3 - 12
  • [39] Information Security Risk Management: Handbook for ISO/IEC 27001
    Lomas, Elizabeth
    [J]. RECORDS MANAGEMENT JOURNAL, 2011, 21 (03) : 239 - +
  • [40] A proposal of metrics for software development based on the ISO/IEC 29110 standard
    Mejia, Jezreel
    Bonilla, Edgar
    Faustino, Israel
    Jhordany, Einar
    Villanueva, Elizabeth
    [J]. APPLICATIONS IN SOFTWARE ENGINEERING, 2021, : 58 - 65