Title :
An enterprise assurance framework
Author :
Landoll, Douglas J. ; Williams, Jeffrey R.
Author_Institution :
Arca Syst. Inc., Vienna, VA, USA
Abstract :
The paper explores generating and conveying confidence in enterprise security. An enterprise assurance framework provides a structure enterprise assurance evidence that strengthens and clarifies the overall enterprise assurance argument. The structure and components of these arguments are defined and then applied to an enterprise. Finally, standards of evidence and evidence trade-offs are mentioned. The paper is largely based on a recent NIST internal report called “A Framework for Reasoning about Assurance”
Keywords :
business data processing; security of data; NIST internal report; confidence; enterprise assurance framework; enterprise security; evidence standards; evidence trade-offs; Documentation; Ice; Information security; Information systems; NIST; Protection;
Conference_Titel :
Enabling Technologies: Infrastructure for Collaborative Enterprises, 1996. Proceedings of the 5th Workshop on
Conference_Location :
Stanford, CA
Print_ISBN :
0-8186-7446-6
DOI :
10.1109/ENABL.1996.555176