A multifaceted, evaluation of the reference model of information assurance & security

被引:10
作者
Cherdantseva, Yulia [1 ]
Hilton, Jeremy [2 ]
Rana, Omer [1 ]
Ivins, Wendy [1 ]
机构
[1] Cardiff Univ, Sch Comp Sci & Informat, Cardiff, S Glam, Wales
[2] Cranfield Univ, Def Acad UK, Ctr Cyber Secur & Informat Syst, Cardiff, S Glam, Wales
关键词
Information Security; Information Assurance; Conceptual model; Reference model; Analytical evaluation; Empirical evaluation;
D O I
10.1016/j.cose.2016.09.007
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The evaluation of a conceptual model, which is an outcome of a qualitative research, is an arduous task due to the lack of a rigorous basis for evaluation. Overcoming this challenge, the paper at hand presents a detailed example of a multifaceted evaluation of a Reference Model of Information Assurance & Security (RMIAS), which summarises the knowledge acquired by the Information Assurance & Security community to date in one all-encompassing model. A combination of analytical and empirical evaluation methods is exploited to evaluate the RMIAS in a sustained way overcoming the limitations of separate methods. The RMIAS is analytically evaluated regarding the quality criteria of conceptual models and compared with existing models. Twenty-six semi-structured interviews with IAS experts are conducted to test the merit of the RMIAS. Three workshops and a case study are carried out to verify the practical value of the model. The paper discusses the evaluation methodology and evaluation results. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:45 / 66
页数:22
相关论文
共 45 条
[1]  
Al-Hamdani W.A., 2009, InfoSecCD '09, P84
[3]   Towards a document-driven approach for designing reference models: From a conceptual process model to its application [J].
Andreas, Jede ;
Frank, Teuteberg .
JOURNAL OF SYSTEMS AND SOFTWARE, 2016, 111 :254-269
[4]  
[Anonymous], 2001, Security Engineering: A Guide to Building Dependable Distributed Systems
[5]  
[Anonymous], 2005, 27002 ISOIEC
[6]  
[Anonymous], 1998, Fighting Computer Crime: A New Framework for Protecting Information
[7]  
[Anonymous], 2012, PRINCIPLES INFORM SE
[8]  
[Anonymous], 2001, P 2001 IEEE WORKSH I
[9]   Basis for an integrated security ontology according to a systematic review of existing proposals [J].
Blanco, Carlos ;
Lasheras, Joaquin ;
Fernandez-Medina, Eduardo ;
Valencia-Garcia, Rafael ;
Toval, Ambrosio .
COMPUTER STANDARDS & INTERFACES, 2011, 33 (04) :372-388
[10]  
Cabinet Office, 2014, GOV SEC CLASS VER 1