A Supporting Tool for IT System Security Specification Evaluation Based on ISO/IEC 15408 and ISO/IEC 18045

被引:0
|
作者
Bao, Da [1 ]
Goto, Yuichi [1 ]
Cheng, Jingde [1 ]
机构
[1] Saitama Univ, Dept Informat & Comp Sci, Saitama, Japan
关键词
IT security evaluation; ISO/IEC; 15408; 18045; Security target;
D O I
10.1007/978-3-030-26142-9_1
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In evaluation and certification framework based on ISO/IEC 15408 and ISO/IEC 18045, a Security Target, which contains the specifications of all security functions of the target system, is the most important document. Evaluation on Security Targets must be performed as the first step of the whole evaluation process. However, evaluation on Security Targets based on ISO/IEC 15408 and ISO/IEC 18045 is very complex. Evaluation process involves of many tasks and costs lots of time when evaluation works are performed by human. Besides, it is also difficult to ensure that evaluation is fair and no subjective mistakes. These issues not only may result in consuming a lot of time, but also may affect the correctness, accuracy, and fairness of evaluation results. Thus, it is necessary to provide a supporting tools that supports all tasks related to the evaluation process automatically to improve the quality of evaluation results at the same time reduce the complexity of all evaluator and certifiers' work. However, there is no such supporting tool existing until now. This paper proposes a supporting tool, called Security Target Evaluator, that provides comprehensive facilities to support the whole process of evaluation on Security Targets based on ISO/IEC 15408 and ISO/IEC 18045.
引用
收藏
页码:3 / 14
页数:12
相关论文
共 50 条
  • [21] Introduction and evaluation of development system security process of ISO/IEC TR 15504
    Lee, ES
    Lee, KW
    Kim, TH
    Jung, IH
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 1, 2004, 3043 : 451 - 460
  • [22] AUTOMATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM BASED ON THE ISO/IEC 27001 STANDARD
    de la Rosa Martin, Tonyse
    [J]. REVISTA UNIVERSIDAD Y SOCIEDAD, 2021, 13 (05): : 495 - 506
  • [23] 9 YEARS OF AN ISO IEC SECRETARIAT ON IT SECURITY
    CALKIN, A
    [J]. COMPUTER STANDARDS & INTERFACES, 1995, 17 (01) : 139 - 143
  • [24] Normalization of Software Risk Assessment Results in Legal Metrology Based on ISO/IEC 18045 Vulnerability Analysis
    Esche, Marko
    Salwiczek, Felix
    Toro, Federico Grasso
    [J]. PROCEEDINGS OF THE 2019 FEDERATED CONFERENCE ON COMPUTER SCIENCE AND INFORMATION SYSTEMS (FEDCSIS), 2019, : 443 - 447
  • [25] The Evaluation of the Electronic Services with Accordance to IT-security Requirements Based on ISO/IEC 27001
    Livshitz, Ilya I.
    Nikiforova, Kseniya A.
    Lontsikh, Pavel A.
    Karaseva, Viktoria A.
    [J]. PROCEEDINGS OF THE 2016 IEEE CONFERENCE ON QUALITY MANAGEMENT, TRANSPORT AND INFORMATION SECURITY, INFORMATION TECHNOLOGIES (IT&MQ&IS), 2016,
  • [26] Customized Diagnostic Tool for The Security Maturity Level of The Enterprise Information Based on ISO/IEC 27001
    Lopez-Leyva, Josue A.
    Kanter-Ramirez, Christopher A.
    Morales-Martinez, Jose P.
    [J]. 2020 8TH EDITION OF THE INTERNATIONAL CONFERENCE IN SOFTWARE ENGINEERING RESEARCH AND INNOVATION (CONISOFT 2020), 2020, : 147 - 153
  • [27] A blockchain-enabled IoT auditing management system complying with ISO/IEC 15408-2
    Cha, Shi-Cho
    Meng, Weizhi
    Li, Wen-Wei
    Yeh, Kuo-Hui
    [J]. COMPUTERS & INDUSTRIAL ENGINEERING, 2023, 178
  • [28] ISO/IEC Competence Requirements for Information Security Professionals
    Miloslayskaya, Natalia
    Tolstoy, Alexander
    [J]. INFORMATION SECURITY EDUCATION FOR A GLOBAL DIGITAL SOCIETY, WISE 10, 2017, 503 : 135 - 146
  • [29] NEW STANDARD ISO/IEC 27001:2013 OF INFORMATION SECURITY MANAGEMENT SYSTEM
    Drastich, Martin
    [J]. KNOWLEDGE FOR MARKET USE 2014: MEDIA AND COMMUNICATION IN THE 21ST CENTURY, 2014, : 387 - 393
  • [30] A Model of an Information Security Management System Based on NTC-ISO/IEC 27001 Standard
    Fonseca-Herrera, Omar A.
    Rojas, Alix E.
    Florez, Hector
    [J]. IAENG International Journal of Computer Science, 2021, 48 (02) : 1 - 10